CVE-2024-4784

MEDIUM

GitLab EE <17.0.6-17.2.2 - Auth Bypass

Title source: llm

Description

An issue was discovered in GitLab EE starting from version 16.7 before 17.0.6, version 17.1 before 17.1.4 and 17.2 before 17.2.2 that allowed bypassing the password re-entry requirement to approve a policy.

Scores

CVSS v3 4.2
EPSS 0.0002
EPSS Percentile 4.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-305 CWE-287
Status published

Affected Products (1)

gitlab/gitlab < 17.0.6

Timeline

Published Aug 08, 2024
Tracked Since Feb 18, 2026