CVE-2024-8754
Description
An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed provider identities when JWT authentication is configured.
Summary dbcve.org
Improper input validation in GitLab allows attackers to link arbitrary unclaimed external identity provider (IdP) identities to existing GitLab accounts when JWT authentication is configured, enabling account squatting and potential privilege escalation by claiming identities that belong to other users.
Mitigation
Upgrade GitLab to versions 17.1.7, 17.2.5, 17.3.2 or later. If immediate upgrade is not possible, review and restrict JWT authentication configuration to prevent unauthorized identity linking.