Medium severity6.8NVD Advisory· Published Aug 8, 2024· Updated Jun 17, 2026
CVE-2024-3035
CVE-2024-3035
Description
A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 8.12
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=8.12.0,<17.0.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.12.0,<17.0.6
- Range: starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/452297nvdBroken Link
- hackerone.com/reports/2424715nvdPermissions Required
News mentions
1- GitLab Patch Release: 17.2.2, 17.1.4, 17.0.6GitLab Security Releases · Aug 7, 2024