HIGH
CVE-2024-3035
CVSS
8.1
Description
A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.
Summary dbcve.org
A permission check vulnerability in GitLab CE/EE allows LFS (Large File Storage) tokens to bypass intended authorization controls and read/write to user-owned repositories when they should not have access. This is a classic authorization bypass where the LFS token validation fails to properly check repository permissions.
Mitigation
Upgrade GitLab to version 17.0.6, 17.1.4, or 17.2.2 or later to patch the permission check vulnerability. Alternatively, review and restrict LFS token usage if immediate upgrade is not feasible.
Weakness (CWE)
CWE-639
Authorization Bypass (IDOR)
EPSS Score
0.36%
Probability of exploitation in next 30 days
29.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.