CVE-2024-12093

CVE Details

Basic Information

Title CVE-2024-12093
Type cve
Published 2025-05-22T15:16:03
Last Seen 2025-05-22T15:22:35

CVSS Information

Base Score 6.8 (MEDIUM)
Attack Vector NETWORK
Attack Complexity HIGH
Privileges Required LOW
User Interaction NONE
Scope UNCHANGED
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact NONE

AI Analysis

AI Description A vulnerability in GitLab CE/EE allows attackers to modify SAML responses due to improper XPath validation, potentially leading to authentication bypass and impersonation of users.
AI Severity Medium
Vendor GitLab Inc.
Product GitLab CE/EE
Affected Version 11.1 before 17.10.7, 17.11 before 17.11.3, 18.0 before 18.0.1

Additional Information

CVE List CVE-2024-12093
CWE List CWE-1288
Bulletin Family cve

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to…

CVSS Score Summary

Base Score: %!f(string=#) (MEDIUM)

View Full CVE Details

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.