CVE-2024-3035: Authorization Bypass Through User-Controlled Key in GitLab
A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-3035?
CVE-2024-3035 is classified as a medium severity vulnerability due to its ability to allow unauthorized access to user-owned repositories.
How do I fix CVE-2024-3035?
To fix CVE-2024-3035, you should upgrade GitLab to version 17.0.6, 17.1.4, or 17.2.2 or later.
What versions of GitLab are affected by CVE-2024-3035?
CVE-2024-3035 affects all versions of GitLab from 8.12 to prior 17.0.6, and specific versions 17.1 and 17.2 before 17.1.4 and 17.2.2 respectively.
What type of vulnerability is CVE-2024-3035?
CVE-2024-3035 is a permission check vulnerability that allows unauthorized LFS token access to user repositories.
Is there a workaround for CVE-2024-3035?
There is no specific workaround for CVE-2024-3035; the best solution is to apply the recommended software update.