CVE-2024-12093Improper Validation of Consistency within Input in Gitlab

Severity
6.8MEDIUMNVD
EPSS
0.1%
top 82.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 22

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.6 | Impact: 5.2

Affected Packages5 packages

CVEListV5gitlab/gitlab11.117.10.7+2
NVDgitlab/gitlab11.1.017.10.7+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-7rfw-87cg-pgwh: An issue has been discovered in GitLab CE/EE affecting all versions from 112025-05-22
OSV
CVE-2024-12093: An issue has been discovered in GitLab CE/EE affecting all versions from 112025-05-22

📋Vendor Advisories

2
GitLab
CVE-2024-12093: An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper X2025-05-22
Debian
CVE-2024-12093: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 be...2024