CVE-2024-8754
An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed provider identities when JWT authentication is configured.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.4
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.43%
- CWE
- CWE-642
- Published
- 2024-09-12
- Last modified
- 2026-03-13
Affected products
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2026-78655 — Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session
- CVE-2025-49090 — The Matrix specification before 1.16 (i.e., with a room version before 12 and State Resolution...
- CVE-2024-58265 — The snow crate before 0.9.5 for Rust, when stateful TransportState is used, allows incrementing a...
- CVE-2025-54566 — hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to...
- CVE-2024-22387 — External Control of Critical State Data (CWE-642) in the Controller 6000 and Controller 7000...
- CVE-2023-0575 — Remote Code Execution
- CVE-2022-22154 — Junos Fusion: A Satellite Device can be controlled by rewiring it to a foreign AD causing a DoS
- CVE-2020-27872 — This vulnerability allows network-adjacent attackers to bypass authentication on affected...