PT-2024-5975 · Gitlab · Gitlab Ce/Ee+1

·

CVE-2024-0231

·

Published

2024-04-23

·

Updated

2025-01-19

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 12.0 through 17.0.4 GitLab CE/EE versions 17.1 through 17.1.2 GitLab CE/EE versions 17.2 through 17.2.0
Description A resource misdirection vulnerability in GitLab allows an attacker to craft a repository import in such a way as to misdirect commits. The issue is related to shortcomings in the authorization procedure, which can be exploited by a remote attacker to replace code in imported CI/CD pipelines.
Recommendations For GitLab CE/EE versions 12.0 through 17.0.4, update to version 17.0.5 or later. For GitLab CE/EE versions 17.1 through 17.1.2, update to version 17.1.3 or later. For GitLab CE/EE versions 17.2 through 17.2.0, update to version 17.2.1 or later.

Exploit

Fix

Improper Access Control

Special Elements Injection

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06783
BIT-GITLAB-2024-0231
CVE-2024-0231

Affected Products

Gitlab
Gitlab Ce/Ee