CVE Vulnerabilities

CVE-2024-5528

Incomplete Comparison with Missing Factors

Published: Feb 05, 2025 | Modified: Aug 06, 2025
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

Weakness

The product performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab*16.11.6 (excluding)
GitlabGitlab17.0.0 (including)17.0.4 (excluding)
GitlabGitlab17.1.0 (including)17.1.2 (excluding)
GitlabUbuntuesm-apps/xenial*

Potential Mitigations

References