CVE-2024-4784: Authentication Bypass by Primary Weakness in GitLab
An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-4784?
CVE-2024-4784 has a high severity rating due to the potential for unauthorized policy approvals.
How do I fix CVE-2024-4784?
To fix CVE-2024-4784, upgrade your GitLab EE installation to version 17.0.6, 17.1.4, or 17.2.2 or later.
What products are affected by CVE-2024-4784?
CVE-2024-4784 affects GitLab EE versions from 16.7 up to but not including 17.0.6, and versions from 17.1 up to but not including 17.1.4 and from 17.2 up to but not including 17.2.2.
Does CVE-2024-4784 allow for remote exploitation?
CVE-2024-4784 does not involve remote exploitation as it requires authenticated access to GitLab EE.
What impact does CVE-2024-4784 have on GitLab EE users?
CVE-2024-4784 could lead to significant security risks by allowing users to approve policies without proper password verification.