CVE-2024-10219: Incorrect Authorization in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.
Other sources
GitLab has remediated an issue that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific API endpoints.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-10219?
CVE-2024-10219 is considered a high severity vulnerability due to its potential to allow authenticated users to bypass access controls.
How do I fix CVE-2024-10219?
To fix CVE-2024-10219, upgrade GitLab CE/EE to version 18.0.6, 18.1.4, or 18.2.2 or later.
Which versions of GitLab are affected by CVE-2024-10219?
CVE-2024-10219 affects GitLab CE/EE versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2.
What type of attacks are possible due to CVE-2024-10219?
CVE-2024-10219 can allow authenticated users to download private artifacts, effectively bypassing access controls.
How can I identify if my GitLab instance is vulnerable to CVE-2024-10219?
You can identify if your GitLab instance is vulnerable to CVE-2024-10219 by checking if it is running a version between 15.6 and 18.0.6, or between 18.1 and 18.1.4, or between 18.2 and 18.2.2.