MEDIUM

CVE-2024-4612

Gitlab GitLab 2024-09-12 CVSS v3.1
CVSS
6.1

Description

An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

Summary dbcve.org

An open redirect vulnerability exists in GitLab EE's OAuth authentication flow across versions 12.9 through 17.3.1 (before patched releases). The vulnerability allows attackers to manipulate the OAuth redirect URI, potentially breaking the flow and enabling account takeover by hijacking session tokens or authorization codes.

Mitigation

Upgrade GitLab EE to version 17.1.7, 17.2.5, 17.3.2 or later. For systems unable to upgrade immediately, restrict OAuth provider configurations and monitor for suspicious redirect patterns in authentication requests.

Weakness (CWE)

CWE-601 Open Redirect

EPSS Score

0.39%
Probability of exploitation in next 30 days
32.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE