CVE-2024-8114 : GITLAB COMMUNITY EDITION/ENTERPRISE EDITION UP TO 17.4.4/17.5.2/17.6.0 PERSONAL ACCESS TOKEN AUTHORIZATION

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim’s Personal Access Token (PAT) to escalate privileges.

References

https://gitlab.com/gitlab-org/gitlab/-/issues/480494

https://hackerone.com/reports/2649822

For More Information

CVERecord

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-8114 : GITLAB COMMUNITY EDITION/ENTERPRISE EDITION UP TO 17.4.4/17.5.2/17.6.0 PERSONAL ACCESS TOKEN AUTHORIZATION

CVE-2024-8114 : GITLAB COMMUNITY EDITION/ENTERPRISE EDITION UP TO 17.4.4/17.5.2/17.6.0 PERSONAL ACCESS TOKEN AUTHORIZATION

Description An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and

CVE-2024-49052 : MICROSOFT AZURE FUNCTIONS POLICYWATCH MISSING AUTHENTICATION

CVE-2024-49052 : MICROSOFT AZURE FUNCTIONS POLICYWATCH MISSING AUTHENTICATION

Description Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.

CVE-2024-49035 : MICROSOFT PARTNER CENTER PARTNER.MICROSOFT.COM PRIVILEGES MANAGEMENT

CVE-2024-49035 : MICROSOFT PARTNER CENTER PARTNER.MICROSOFT.COM PRIVILEGES MANAGEMENT

Description An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network. References