Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.

INFO

Published Date :

2025-01-09T06:33:13.241Z

Last Modified :

2025-01-09T15:29:59.641Z

Source :

GitLab
AFFECTED PRODUCTS

The following products are affected by CVE-2024-13041 vulnerability.

Vendors Products
Gitlab
  • Gitlab

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact