CVE-2024-5470: Improper Access Control in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with adminpushrules permission may have been able to create project-level deploy tokens.
Other sources
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2 where a Guest user with adminpushrules permission may have been able to create project-level deploy tokens. This is a low severity issue (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N, 3.8). It is now mitigated in the latest release and is assigned CVE-2024-5470.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.0.4Fixed in 17.1.2 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 17.0.4 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 17.1.2
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-5470?
CVE-2024-5470 is classified as a high-severity vulnerability due to its potential to allow unauthorized project-level deploy token creation.
How do I fix CVE-2024-5470?
To fix CVE-2024-5470, upgrade to GitLab version 17.0.4 or 17.1.2 or later.
Who is affected by CVE-2024-5470?
CVE-2024-5470 affects all GitLab CE/EE versions starting from 17.0 prior to 17.0.4 and from 17.1 prior to 17.1.2.
What does CVE-2024-5470 allow an attacker to do?
CVE-2024-5470 allows a Guest user with `admin_push_rules` permission to create project-level deploy tokens.
When was CVE-2024-5470 disclosed?
CVE-2024-5470 was disclosed along with the affected versions of GitLab, which were identified in 2024.