Improper access control in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2024-13041
Published: January 9, 2025
Vulnerability identifier: #VU102499
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-13041
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to instance SAML does not respect external_provider configuration. A remote user which is not marked as external can gain access to internal projects or groups.
Affected software
GitLab Enterprise Edition
Gitlab Community Edition
Gitlab Community Edition
How to mitigate CVE-2024-13041
Install updates from vendor's website.
GitLab Enterprise Edition - addressed in versions 17.5.5, 17.6.3, 17.7.1
Gitlab Community Edition - addressed in versions 17.5.5, 17.6.3, 17.7.1
Gitlab Community Edition - addressed in versions 17.5.5, 17.6.3, 17.7.1