CVE-2024-3958
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.
Summary dbcve.org
This is a UI deception/social engineering vulnerability in GitLab where the web application displays repository information differently from what the git command line interface would show. Attackers can exploit this discrepancy to trick users into cloning malicious code by making the web UI appear trustworthy while the actual git operation fetches different content.
Mitigation
Upgrade GitLab to version 17.0.6, 17.1.4, 17.2.2 or later to resolve the web-to-CLI discrepancy that enables this social engineering attack.