CVE Vulnerabilities

CVE-2024-11668

Insufficient Session Expiration

Published: Nov 26, 2024 | Modified: Dec 12, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results.

Weakness

According to WASC, “Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization.”

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 16.11.0 (including) 17.4.5 (excluding)
Gitlab Gitlab 17.5.0 (including) 17.5.3 (excluding)
Gitlab Gitlab 17.6.0 (including) 17.6.0 (including)
Gitlab Ubuntu esm-apps/xenial *

Potential Mitigations

References