/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-8754

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-8754

Severity

6.4

Medium

CVSS V3

Summary

External Control of Critical State Data in GitLab

Description

An issue has been discovered in GitLab EE/CE affecting all versions from 16.9.7 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2. An improper input validation error allows attacker to squat on accounts via linking arbitrary unclaimed provider identities when JWT authentication is configured.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing