MEDIUM

CVE-2024-10219

Gitlab GitLab 2025-08-13 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.

Summary dbcve.org

GitLab CE/EE versions prior to 18.0.6, 18.1.4, and 18.2.2 contain an access control bypass vulnerability in specific API endpoints that allows authenticated users to download private artifacts they should not have access to, exploiting insufficient permission validation under certain conditions.

Mitigation

Upgrade GitLab to version 18.0.6, 18.1.4, 18.2.2 or later. After upgrading, verify that artifact access controls properly restrict unauthorized downloads through the affected API endpoints.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.43%
Probability of exploitation in next 30 days
37.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE