CVE-2024-6685: Authorization Bypass Through User-Controlled Key in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2, where group runners information was disclosed to unauthorised group members.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-6685?
CVE-2024-6685 is considered a medium severity vulnerability due to unauthorized disclosure of group runner information.
How do I fix CVE-2024-6685?
To fix CVE-2024-6685, upgrade GitLab to version 17.1.7 or later, 17.2.5 or later, or 17.3.2 or later.
Which versions are affected by CVE-2024-6685?
CVE-2024-6685 affects GitLab CE/EE versions from 16.7 up to but not including 17.1.7, 17.2 up to but not including 17.2.5, and 17.3 up to but not including 17.3.2.
What type of vulnerability is CVE-2024-6685?
CVE-2024-6685 is a privacy vulnerability that involves unauthorized access to group runner information.
Who is impacted by CVE-2024-6685?
Unauthorized group members in GitLab CE/EE installations prior to the fixed versions are impacted by CVE-2024-6685.