Improper access control in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2024-9633
Published: December 12, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the domain confusion issue in GitLab Pages Unique Domain Implementation. A remote user can create a group with a name matching an existing unique Pages domain, leading to domain confusion attacks.
Affected software
Gitlab Community Edition
How to mitigate CVE-2024-9633
Gitlab Community Edition - addressed in versions 17.4.6, 17.5.4, 17.6.2