CVE-2024-9633 is a high-severity vulnerability in GitLab CE/EE, affecting versions 16.3 through 17.4.1, 17.5 through 17.5.3, and 17.6 through 17.6.1. This flaw allows an unauthenticated attacker to create a group with a name that conflicts with an existing unique Pages domain, potentially enabling domain confusion attacks. The CVSS score of 7.5 (HIGH) indicates a network-based attack with low complexity, requiring no privileges or user interaction, and leading to high availability impact. While the vulnerability has received some community discussion and media coverage, there is currently no evidence of active exploitation, nor are public exploit codes like Metasploit or Nuclei available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.3.0, < 17.4.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 16.3.0, < 17.4.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 17.5.0, < 17.5.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 17.5.0, < 17.5.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 17.6.0, < 17.6.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.