CVE-2024-9387: URL Redirection to Untrusted Site ('Open Redirect') in GitLab
An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9387?
CVE-2024-9387 has been classified as a vulnerability that allows open redirects, which can lead to phishing attacks or unauthorized access.
How do I fix CVE-2024-9387?
To fix CVE-2024-9387, upgrade your GitLab installation to a version that is at least 17.4.6, 17.5.4, or 17.6.2, depending on your current version.
What versions are affected by CVE-2024-9387?
CVE-2024-9387 affects GitLab CE from version 11.8 up to but not including 17.4.6, and GitLab EE from 17.5 before 17.5.4 and 17.6 before 17.6.2.
What type of attacks can be carried out using CVE-2024-9387?
CVE-2024-9387 can allow attackers to perform open redirects which can be utilized for phishing or redirecting users to malicious sites.
Is CVE-2024-9387 present in the latest version of GitLab?
No, CVE-2024-9387 is not present in GitLab versions 17.4.6 and later, 17.5.4 and later, or 17.6.2 and later.