CVE-2024-9633: Incorrect Ownership Assignment in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions starting from 17.6 before 17.6.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9633?
CVE-2024-9633 has a medium severity level due to its potential impact on group naming and user privilege escalation.
How do I fix CVE-2024-9633?
To fix CVE-2024-9633, upgrade to GitLab versions 17.4.2, 17.5.4, or 17.6.2 or later.
What versions of GitLab are affected by CVE-2024-9633?
CVE-2024-9633 affects all versions of GitLab from 16.3 to before 17.4.2, from 17.5 to before 17.5.4, and from 17.6 to before 17.6.2.
Can CVE-2024-9633 lead to unauthorized access?
Yes, CVE-2024-9633 could allow attackers to create groups with names that can lead to unauthorized access or privilege escalation.
Is there a known exploit for CVE-2024-9633?
While there is no public exploit available for CVE-2024-9633, the issue itself poses a significant risk if not patched.