PT-2024-4134 · Gitlab · Gitlab
Andrew Winata
+1
·
Published
2024-05-23
·
Updated
2024-12-13
·
CVE-2024-5258
CVSS v3.1
4.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab versions 13.2.4 through 16.10.5
GitLab versions 16.11 through 16.11.2
GitLab versions 17.0 through 17.0.0
Description
An authorization issue exists where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic, potentially allowing a remote attacker to bypass existing security restrictions.
Recommendations
For GitLab versions 13.2.4 through 16.10.5, update to version 16.10.6 or later.
For GitLab versions 16.11 through 16.11.2, update to version 16.11.3 or later.
For GitLab versions 17.0 through 17.0.0, update to version 17.0.1 or later.
Exploit
Fix
Incorrect Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab