CVE-2024-5470 is a low-severity vulnerability affecting GitLab CE/EE versions 17.0 prior to 17.0.4 and 17.1 prior to 17.1.2. It allows a Guest user with admin_push_rules permission to create project-level deploy tokens, potentially leading to unauthorized access or modification of project data. The CVSS score is 2.7 (LOW), indicating a network-based attack with low complexity and high privileges required, resulting in a low impact on integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.0.0, < 17.0.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 17.0.0, < 17.0.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 17.1.0, < 17.1.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 17.1.0, < 17.1.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 17.0, < 17.0.4CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.