logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-4024

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-4024

Description:
An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.8 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1. Under certain conditions, an attacker with their Bitbucket account credentials may be able to take over a GitLab account linked to another user's Bitbucket account, if Bitbucket is used as an OAuth 2.0 provider on GitLab.
Last updated date:
12/12/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
12/12/2024
Reference url to background

https://gitlab.com/gitlab-org/gitlab/-/issues/452426

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy