Vulnerability CVE-2024-4283


Published: 2024-09-16   Modified: 2024-09-17

Description:
An issue has been discovered in GitLab EE affecting all versions starting from 11.1 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. Under certain conditions an open redirect vulnerability could allow for an account takeover by breaking the OAuth flow.

 References:
https://gitlab.com/gitlab-org/gitlab/-/issues/458502
https://hackerone.com/reports/2474286

Copyright 2025, cxsecurity.com

 

Back to Top