GitLab Security Restriction Bypass Vulnerability
Last Update Date:
27 Sep 2024
Release Date:
19 Sep 2024
3438
Views
RISK: Medium Risk
TYPE: Servers - Other Servers
A vulnerability has been identified in GitLab. A remote attacker could exploit this vulnerability to trigger security restriction bypass on the targeted system.
[Updated on 2024-09-27]
Updated System / Technologies affected, Solutions and Related Links.
Impact
- Security Restriction Bypass
System / Technologies affected
- GitLab Community Edition (CE) versions prior to 17.3.3, 17.2.7, 17.1.8, 17.0.8 and 16.11.10
- GitLab Enterprise Edition (EE) versions prior to 17.3.3, 17.2.7, 17.1.8, 17.0.8 and 16.11.10
- GitLab Community Edition (CE) versions prior to 16.10.10, 16.9.11, 16.8.10, 16.7.10, 16.6.10, 16.5.10, 16.4.7, 16.3.9, 16.2.11, 16.1.8, and 16.0.10
- GitLab Enterprise Edition (EE) versions prior to 16.10.10, 16.9.11, 16.8.10, 16.7.10, 16.6.10, 16.5.10, 16.4.7, 16.3.9, 16.2.11, 16.1.8, and 16.0.10
Solutions
Before installation of the software, please visit the vendor web-site for more details.
Apply fixes issued by the vendor:
- https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/
- https://about.gitlab.com/releases/2024/09/25/patch-release-gitlab-16-10-10-released/
Vulnerability Identifier
Source
Related Link
Related Tags
Share with