CVE-2024-4784Authentication Bypass by Primary Weakness in Gitlab

Severity
5.4MEDIUMNVD
EPSS
0.0%
top 95.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8

Description

An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5

Affected Packages5 packages

CVEListV5gitlab/gitlab16.717.0.6+2
NVDgitlab/gitlab16.7.017.0.6+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2024-4784: An issue was discovered in GitLab EE starting from version 162024-08-08
GHSA
GHSA-662c-cj8q-qc4g: An issue was discovered in GitLab EE starting from version 162024-08-08

📋Vendor Advisories

2
GitLab
CVE-2024-4784: An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassin2024-08-08
Debian
CVE-2024-4784: gitlab - An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, v...2024