Home
MEDIUM: 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
16.11 (semver) before 17.4.5
affected
17.5 (semver) before 17.5.3
affected
17.6 (semver) before 17.6.1
affected
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially bypass authentication controls, allowing unauthorized access to streaming results.
Problem types
CWE-613: Insufficient Session Expiration
Product status
16.11 (semver) before 17.4.5
17.5 (semver) before 17.5.3
17.6 (semver) before 17.6.1
Credits
This vulnerability has been discovered internally by GitLab team members Dylan Griffith and Heinrich Lee Yu
References
gitlab.com/gitlab-org/gitlab/-/issues/456922 (GitLab Issue #456922)