CVE-2024-6678: Authentication Bypass by Spoofing in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6678?
CVE-2024-6678 is classified as a critical vulnerability affecting GitLab versions from 8.14 up to 17.1.7, and from 17.2.0 up to 17.2.5 and 17.3.0 up to 17.3.2.
How do I fix CVE-2024-6678?
To mitigate CVE-2024-6678, upgrade GitLab to versions 17.1.7, 17.2.5, or 17.3.2 or later.
What are the potential impacts of CVE-2024-6678?
If exploited, CVE-2024-6678 allows an attacker to trigger a pipeline as an arbitrary user.
Which GitLab versions are affected by CVE-2024-6678?
CVE-2024-6678 affects GitLab CE/EE versions from 8.14 to 17.1.7, 17.2.0 to 17.2.5, and 17.3.0 to 17.3.2.
Is CVE-2024-6678 exclusive to a specific GitLab edition?
No, CVE-2024-6678 affects both GitLab Community Edition (CE) and Enterprise Edition (EE).