CVE-2024-5258: Authorization Bypass Through User-Controlled Key in GitLab
An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.
Other sources
An authorization vulnerability exists within GitLab from versions 16.10 up to 16.10.6, 16.11 up to 16.11.3, and 17.0 up to 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic. This is a medium severity issue (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N, 4.4). It is now mitigated in the latest release and is assigned CVE-2024-5258.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GitLabto a version that resolves this vulnerability.Fixed in 16.10.6 - Upgrade
Upgrade
GitLabto a version that resolves this vulnerability.Fixed in 16.11.3 - Upgrade
Upgrade
GitLabto a version that resolves this vulnerability.Fixed in 17.0.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5258?
CVE-2024-5258 is classified as a medium-severity authorization vulnerability.
How do I fix CVE-2024-5258?
To fix CVE-2024-5258, update GitLab to version 16.10.6, 16.11.3, or 17.0.1 or later.
What specific versions are affected by CVE-2024-5258?
CVE-2024-5258 affects GitLab versions 16.10.0 to 16.10.5, 16.11.0 to 16.11.2, and 17.0.0.
What type of attack does CVE-2024-5258 enable?
CVE-2024-5258 enables authenticated attackers to bypass pipeline authorization logic through a crafted naming convention.
Who is impacted by CVE-2024-5258?
Users of GitLab versions 16.10, 16.11, and 17.0 below the specified patched versions are impacted by CVE-2024-5258.