# CVE-2024-5528

## Summary

- **CVE ID:** CVE-2024-5528
- **Severity:** LOW
- **CVSS Score:** 3.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
- **CWE:** CWE-1023
- **Published:** Feb 5, 2025
- **Last Modified:** Mar 13, 2026

## Description

An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.

## Affected Products

- GitLab — GitLab (0.0)
- GitLab — GitLab (17.0)
- GitLab — GitLab (17.1)

## References

- [CNA](https://gitlab.com/gitlab-org/gitlab/-/issues/464558)
- [CNA](https://hackerone.com/reports/2523654)
- [CISA-ADP](https://about.gitlab.com/releases/2024/07/10/patch-release-gitlab-17-1-2-released/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.41%
- **EPSS Percentile:** 34.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._