EXECUTIVE SUMMARY:
GitLab has address two vulnerabilities for their both editions Community Edition (CE) and Enterprise Edition (EE) platforms. These two critical vulnerabilities that could potentially enable attackers to bypass authorization mechanisms and gain access to protected variables.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
GitLab has address two vulnerabilities for their both editions Community Edition (CE) and Enterprise Edition (EE) platforms. These two critical vulnerabilities that could potentially enable attackers to bypass authorization mechanisms and gain access to protected variables.[emaillocker id="1283"]
CVE-2024-0199 – This is an authorization bypass vulnerability affecting a wide range of GitLab versions. This flaw allowed attackers to craft a payload that could be used in an old feature branch to bypass CODEOWNERS restrictions, enabling unauthorized access to protected variables.
CVE-2024-1299 – This Vulnerability is a privilege escalation issue that affected versions 16.8 and 16.9. This flaw allowed users with the custom role of manage_group_access_tokens to rotate and view group access tokens as if they had owner permissions, posing a medium severity risk.
Recommendation:
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/gitlab-vulnerability-attackers-steal/
[/emaillocker]