CVE Vulnerabilities

CVE-2024-9633

Incorrect Ownership Assignment

Published: Nov 14, 2024 | Modified: Dec 12, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions starting from 17.6 before 17.6.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.

Weakness

The product assigns an owner to a resource, but the owner is outside of the intended control sphere.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 16.3.0 (including) 17.4.2 (excluding)
Gitlab Gitlab 17.5.0 (including) 17.5.4 (excluding)
Gitlab Gitlab 17.6.0 (including) 17.6.2 (excluding)

Potential Mitigations

References