HIGH

CVE-2024-3035

Gitlab GitLab 2024-08-08 CVSS v3.1
CVSS
8.1

Description

A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

Summary dbcve.org

A permission check vulnerability in GitLab CE/EE allows LFS (Large File Storage) tokens to bypass intended authorization controls and read/write to user-owned repositories when they should not have access. This is a classic authorization bypass where the LFS token validation fails to properly check repository permissions.

Mitigation

Upgrade GitLab to version 17.0.6, 17.1.4, or 17.2.2 or later to patch the permission check vulnerability. Alternatively, review and restrict LFS token usage if immediate upgrade is not feasible.

Weakness (CWE)

CWE-639 Authorization Bypass (IDOR)

EPSS Score

0.36%
Probability of exploitation in next 30 days
29.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE