CVE-2024-1347 — Authentication Bypass by Spoofing in Gitlab
Severity
5.3MEDIUMNVD
EPSS
0.0%
top 97.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 25
Latest updateJul 30
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages5 packages
🔴Vulnerability Details
2📋Vendor Advisories
4Red Hat
▶
GitLab▶
CVE-2024-1347: An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions start↗2024-04-25
Debian▶
CVE-2024-1347: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions before 16.9....↗2024