Medium severity6.8NVD Advisory· Published Nov 14, 2024· Updated Jun 17, 2026
CVE-2024-7404
CVE-2024-7404
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 17.2
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=17.2.0,<17.3.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=17.2.0,<17.3.7
- Range: from 17.2 prior to 17.3.7, from 17.4 prior to 17.4.4, from 17.5 prior to 17.5.2
Patches
Vulnerability mechanics
References
3- about.gitlab.com/releases/2024/11/13/patch-release-gitlab-17-5-2-released/nvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/476670nvdBroken Link
- hackerone.com/reports/2627925nvdPermissions Required
News mentions
1- GitLab Patch Release: 17.5.2, 17.4.4, 17.3.7GitLab Security Releases · Nov 13, 2024