#VU88982 Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2024-4024
Published: April 25, 2024
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user with their Bitbucket account credentials can take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.