GitLab Account Takeover Vulnerability Affects All Versions
CVE-2024-4024

8.8HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
25 April 2024

What is CVE-2024-4024?

A security vulnerability has been identified in GitLab CE/EE that allows for potential account takeovers under specific conditions. If a user has linked their GitLab account to a Bitbucket account, an attacker with valid Bitbucket account credentials could exploit this vulnerability due to improper handling of OAuth 2.0 authentication processes. This represents a significant risk for users utilizing Bitbucket as an OAuth 2.0 provider within their GitLab setup. Affected versions range from 7.8 until pre-16.9.6, 16.10 up to pre-16.10.4, and 16.11 until pre-16.11.1. Immediate actions are recommended for users to safeguard their accounts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

GitLab 7.8 < 16.9.6

GitLab 16.10 < 16.10.4

GitLab 16.11 < 16.11.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability has been discovered internally by GitLab team members [Sam Word](https://gitlab.com/SamWord) and [Rodrigo Tomonari](https://gitlab.com/rodrigo.tomonari)
.