MEDIUM

CVE-2024-3958

Gitlab GitLab 2024-08-08 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

Summary dbcve.org

This is a UI deception/social engineering vulnerability in GitLab where the web application displays repository information differently from what the git command line interface would show. Attackers can exploit this discrepancy to trick users into cloning malicious code by making the web UI appear trustworthy while the actual git operation fetches different content.

Mitigation

Upgrade GitLab to version 17.0.6, 17.1.4, 17.2.2 or later to resolve the web-to-CLI discrepancy that enables this social engineering attack.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

0.32%
Probability of exploitation in next 30 days
25.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE