VDB

CVE-2024-7404

CVE-2024-7404 PUBLISHED

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

EPSS 0.37% · 59.2th percentile

Risk Scores

EPSS Score
0.37%
59.2th percentile

Affected Products

VendorProductVersions
Bitnamigitlab17.2.0, 17.4.0, 17.5.0
Bitnamigitlab17.4.0, 17.5.0, 17.2.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Nov 12, 2024 CVE Published
  • Nov 13, 2024 PoC Published
  • Nov 14, 2024 Coalition ESS Score
  • Nov 14, 2024 PoC Published
  • Nov 14, 2024 PoC Published
  • Nov 15, 2024 EPSS Score
  • Nov 15, 2024 Coalition ESS Score
  • Nov 27, 2024 Coalition ESS Score
  • Dec 4, 2024 EPSS Score
  • Dec 18, 2024 Coalition ESS Score
  • Dec 21, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›