CVE-2024-1347Authentication Bypass by Spoofing in Gitlab

Severity
5.3MEDIUMNVD
EPSS
0.0%
top 97.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25
Latest updateJul 30

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker through a crafted email address may be able to bypass domain based restrictions on an instance or a group.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

CVEListV5gitlab/gitlab0.016.9.6+2
NVDgitlab/gitlab16.10.016.10.4+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2024-1347: An issue has been discovered in GitLab CE/EE affecting all versions before 162024-04-25
GHSA
GHSA-2x3p-pww2-fg9r: An issue has been discovered in GitLab CE/EE affecting all versions before 162024-04-25

📋Vendor Advisories

4
Red Hat
kernel: Bluetooth: ISO: Check socket flag instead of hcon2024-07-30
Red Hat
gitlab: bypass domain based restrictions on an instance or a group by a crafted email2024-04-25
GitLab
CVE-2024-1347: An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions start2024-04-25
Debian
CVE-2024-1347: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions before 16.9....2024