MEDIUM
CVE-2024-4784
CVSS
5.4
Description
An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy.
Summary dbcve.org
GitLab EE versions 16.7 through 17.2.1 contained an authentication bypass allowing users to approve security policies without re-entering their password, defeating a security control intended to require explicit re-authentication for sensitive policy approvals.
Mitigation
Upgrade GitLab EE to version 17.0.6, 17.1.4, or 17.2.2 or later to resolve the password re-entry bypass.
Weakness (CWE)
CWE-305
CWE-287
Improper Authentication
EPSS Score
0.27%
Probability of exploitation in next 30 days
19.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.