CVE-2024-12570
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.7
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
- EPSS probability
- 0.43%
- CWE
- CWE-270
- Published
- 2024-12-12
- Last modified
- 2026-03-13
Affected products
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows...
- CVE-2026-34853 — Permission bypass vulnerability in the LBS module....
- CVE-2025-55210 — FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes
- CVE-2025-60721 — Windows Administrator Protection Elevation of Privilege Vulnerability
- CVE-2025-9408 — Userspace privilege escalation vulnerability on Cortex M
- CVE-2025-26499 — Under heavy system utilization a random race condition can occur during authentication or token...
- CVE-2025-46406 — A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged...
- CVE-2025-49583 — XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right