CVE-2024-8647: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
An issue was discovered in GitLab affecting all versions starting 15.2 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. On self hosted installs, it was possible to leak the cross site request forgery (CSRF) token to an external site while the Harbor integration was enabled. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N, 5.4). It is now mitigated in the latest release and is assigned CVE-2024-8647.
Other sources
An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.
— MITRE
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8647?
CVE-2024-8647 is considered a medium severity vulnerability due to the risk of anti-CSRF-token leakage.
How do I fix CVE-2024-8647?
To fix CVE-2024-8647, you should update your GitLab installation to version 17.5.4 or later, and 17.6.2 or later if using those specific vulnerable versions.
Which versions are affected by CVE-2024-8647?
CVE-2024-8647 affects GitLab versions 15.2 through 17.4.6, versions prior to 17.5.4, and versions prior to 17.6.2.
What impact does CVE-2024-8647 have on self-hosted GitLab instances?
CVE-2024-8647 allows the leakage of the anti-CSRF-token to external sites when the Harbor integration is enabled.
Is there a workaround for CVE-2024-8647?
There is no official workaround for CVE-2024-8647; updating to a secure version is the recommended action.