An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.
Solution:
The product performs a comparison between entities that must consider multiple factors or characteristics of each entity, but the comparison does not include one or more of these factors.
The product compares two entities in a security-relevant context, but the comparison is incorrect, which may lead to resultant weaknesses.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/464558 | issue tracking exploit permissions required |
https://hackerone.com/reports/2523654 | technical description permissions required exploit |
https://about.gitlab.com/releases/2024/07/10/patch-release-gitlab-17-1-2-released/ | release notes |