CVE Vulnerabilities

CVE-2024-6678

Authentication Bypass by Spoofing

Published: Sep 12, 2024 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
9.9 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Ubuntu
MEDIUM

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.

Weakness

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 8.14.0 (including) 17.1.7 (excluding)
Gitlab Gitlab 17.2.0 (including) 17.2.5 (excluding)
Gitlab Gitlab 17.3.0 (including) 17.3.2 (excluding)
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu upstream *

References