CVE-2024-10219
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.
Summary dbcve.org
GitLab CE/EE versions prior to 18.0.6, 18.1.4, and 18.2.2 contain an access control bypass vulnerability in specific API endpoints that allows authenticated users to download private artifacts they should not have access to, exploiting insufficient permission validation under certain conditions.
Mitigation
Upgrade GitLab to version 18.0.6, 18.1.4, 18.2.2 or later. After upgrading, verify that artifact access controls properly restrict unauthorized downloads through the affected API endpoints.