Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

INFO

Published Date :

2024-11-14T13:02:23.587Z

Last Modified :

2024-11-14T15:08:01.260Z

Source :

GitLab
AFFECTED PRODUCTS

The following products are affected by CVE-2024-7404 vulnerability.

Vendors Products
Gitlab
  • Gitlab

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact