MEDIUM

CVE-2024-4784

Gitlab GitLab 2024-08-08 CVSS v3.1
CVSS
5.4

Description

An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy.

Summary dbcve.org

GitLab EE versions 16.7 through 17.2.1 contained an authentication bypass allowing users to approve security policies without re-entering their password, defeating a security control intended to require explicit re-authentication for sensitive policy approvals.

Mitigation

Upgrade GitLab EE to version 17.0.6, 17.1.4, or 17.2.2 or later to resolve the password re-entry bypass.

Weakness (CWE)

CWE-305
CWE-287 Improper Authentication

EPSS Score

0.27%
Probability of exploitation in next 30 days
19.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE