#VU101739 Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2024-9633
Published: December 12, 2024
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the domain confusion issue in GitLab Pages Unique Domain Implementation. A remote user can create a group with a name matching an existing unique Pages domain, leading to domain confusion attacks.