PT-2024-7210 · Gitlab · Gitlab Ce/Ee+1

Published

2024-08-10

·

Updated

2025-01-27

·

CVE-2024-9623

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 8.16 through 17.2.9 GitLab CE/EE versions 17.3 through 17.3.5 GitLab CE/EE versions 17.4 through 17.4.2
Description An issue was discovered in GitLab CE/EE, which allows deploy keys to push to an archived repository. The issue is related to authorization procedure flaws, potentially allowing a remote attacker to elevate privileges using deploy keys.
Recommendations For GitLab CE/EE versions 8.16 through 17.2.9, update to version 17.2.9 or later. For GitLab CE/EE versions 17.3 through 17.3.5, update to version 17.3.5 or later. For GitLab CE/EE versions 17.4 through 17.4.2, update to version 17.4.2 or later. As a temporary workaround, consider restricting the use of deploy keys to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Missing Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-08549
BIT-GITLAB-2024-9623
CVE-2024-9623

Affected Products

Gitlab
Gitlab Ce/Ee