HIGH
CVE-2024-8641
CVSS
8.8
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. It may have been possible for an attacker with a victim's CI_JOB_TOKEN to obtain a GitLab session token belonging to the victim.
Summary dbcve.org
In affected GitLab versions, an attacker who possesses a victim's CI_JOB_TOKEN (a CI/CD pipeline token) can exploit the application to obtain the victim's GitLab session token, enabling session hijacking and unauthorized access to the victim's account.
Mitigation
Upgrade GitLab to version 17.1.7, 17.2.5, 17.3.2 or later. For older supported branches, apply the equivalent patch. Restrict CI_JOB_TOKEN usage scope as a temporary measure until upgrade is complete.
Weakness (CWE)
CWE-270
EPSS Score
0.49%
Probability of exploitation in next 30 days
40.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.