Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31643 | A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories. |
Solution
Upgrade to versions 17.2.2, 17.1.4, 17.0.6 or above.
Workaround
No workaround given by the vendor.
Wed, 18 Sep 2024 01:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:17.2:*:*:*:*:*:*:* cpe:2.3:a:gitlab:gitlab:8.12.0:*:*:*:*:*:*:* |
Fri, 30 Aug 2024 01:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
Fri, 30 Aug 2024 00:15:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Thu, 08 Aug 2024 23:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| CPEs | cpe:2.3:a:gitlab:gitlab:17.1:*:*:*:*:*:*:* cpe:2.3:a:gitlab:gitlab:17.2:*:*:*:*:*:*:* cpe:2.3:a:gitlab:gitlab:8.12.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| Metrics |
ssvc
|
Thu, 08 Aug 2024 19:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories. | |
| Title | Authorization Bypass Through User-Controlled Key in GitLab | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-09-17T15:29:42.165Z
Reserved: 2024-03-28T02:30:37.528Z
Link: CVE-2024-3035
Updated: 2024-08-08T14:06:55.738Z
Status : Analyzed
Published: 2024-08-08T11:15:12.503
Modified: 2024-08-29T15:55:30.247
Link: CVE-2024-3035
No data.
OpenCVE Enrichment
No data.
EUVD