HIGH

CVE-2024-8754

Gitlab GitLab 2024-09-12 CVSS v3.1
CVSS
8.1

Description

An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed provider identities when JWT authentication is configured.

Summary dbcve.org

Improper input validation in GitLab allows attackers to link arbitrary unclaimed external identity provider (IdP) identities to existing GitLab accounts when JWT authentication is configured, enabling account squatting and potential privilege escalation by claiming identities that belong to other users.

Mitigation

Upgrade GitLab to versions 17.1.7, 17.2.5, 17.3.2 or later. If immediate upgrade is not possible, review and restrict JWT authentication configuration to prevent unauthorized identity linking.

Weakness (CWE)

CWE-642

EPSS Score

0.43%
Probability of exploitation in next 30 days
37th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE