CVE-2024-12570Privilege Context Switching Error in Gitlab

Severity
6.7MEDIUMNVD
EPSS
0.0%
top 94.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:LExploitability: 1.2 | Impact: 5.5

Affected Packages5 packages

CVEListV5gitlab/gitlab13.717.4.6+2
NVDgitlab/gitlab13.7.017.4.6+2
debiandebian/gitlab< gitlab 17.5.5-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-7p75-9h8v-vxq4: An issue has been discovered in GitLab CE/EE affecting all versions starting from 132024-12-12
OSV
CVE-2024-12570: An issue has been discovered in GitLab CE/EE affecting all versions starting from 132024-12-12

📋Vendor Advisories

2
GitLab
CVE-2024-12570: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior2024-12-12
Debian
CVE-2024-12570: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions starting fro...2024