An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.
Fixes

Solution

Upgrade to versions 17.3.2, 17.2.5, 17.1.7 or above.


Workaround

No workaround given by the vendor.

History

Sat, 14 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Fri, 13 Sep 2024 15:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Sep 2024 17:15:00 +0000

Type Values Removed Values Added
Description An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.
Title Incorrect Authorization in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-863
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2024-09-13T14:17:32.500Z

Reserved: 2024-03-20T14:30:41.336Z

Link: CVE-2024-2743

cve-icon Vulnrichment

Updated: 2024-09-13T14:17:32.500Z

cve-icon NVD

Status : Modified

Published: 2024-09-12T17:15:04.177

Modified: 2024-11-21T09:10:25.043

Link: CVE-2024-2743

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.