Token Leakage Vulnerability in GitLab CE/EE
CVE-2024-12570
Key Information:
Badges
What is CVE-2024-12570?
CVE-2024-12570 is a high-risk vulnerability identified in GitLab CE/EE, compromising user session integrity. The flaw enables an attacker to exploit the CI_JOB_TOKEN of a victim to gain unauthorized access to their GitLab session token. This issue affects multiple versions of GitLab from version 13.7 up to 17.4.6, as well as versions 17.5 prior to 17.5.4 and 17.6 prior to 17.6.2. Organizations using these versions should prioritize patching to prevent potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GitLab 13.7 < 17.4.6
GitLab 17.5 < 17.5.4
GitLab 17.6 < 17.6.2
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved