CVE-2024-1525

MEDIUM

GitLab CE/EE <16.7.6-16.8.3-16.9.1 - Auth Bypass

Title source: llm

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Under some specialized conditions, an LDAP user may be able to reset their password using their verified secondary email address and sign-in using direct authentication with the reset password, bypassing LDAP.

Scores

CVSS v3 5.3
EPSS 0.0001
EPSS Percentile 0.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-288
Status published

Affected Products (2)

gitlab/gitlab < 16.7.6
gitlab/gitlab

Timeline

Published Feb 22, 2024
Tracked Since Feb 18, 2026