CVE-2024-4612
Description
An issue has been discovered in GitLab EE affecting all versions starting from 12.9 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.
Summary dbcve.org
An open redirect vulnerability exists in GitLab EE's OAuth authentication flow across versions 12.9 through 17.3.1 (before patched releases). The vulnerability allows attackers to manipulate the OAuth redirect URI, potentially breaking the flow and enabling account takeover by hijacking session tokens or authorization codes.
Mitigation
Upgrade GitLab EE to version 17.1.7, 17.2.5, 17.3.2 or later. For systems unable to upgrade immediately, restrict OAuth provider configurations and monitor for suspicious redirect patterns in authentication requests.