An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.
History

Thu, 09 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jan 2025 06:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.5, starting from 17.6 prior to 17.6.3, and starting from 17.7 prior to 17.7.1. When a user is created via the SAML provider, the external groups setting overrides the external provider configuration. As a result, the user may not be marked as external thereby giving those users access to internal projects or groups.
Title Incorrect User Management in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-286
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2025-01-09T15:29:59.641Z

Reserved: 2024-12-30T10:30:41.109Z

Link: CVE-2024-13041

cve-icon Vulnrichment

Updated: 2025-01-09T15:29:52.252Z

cve-icon NVD

Status : Received

Published: 2025-01-09T07:15:26.497

Modified: 2025-01-09T07:15:26.497

Link: CVE-2024-13041

cve-icon Redhat

No data.