CVE-2024-0231
GitLab vulnerability analysis and mitigation

Overview

A resource misdirection vulnerability was identified in GitLab CE/EE affecting versions 12.0 prior to 17.0.5, 17.1 prior to 17.1.3, and 17.2 prior to 17.2.1. The vulnerability allows attackers to bypass tag check restrictions during project imports, specifically circumventing security measures that prevent tags from being named with SHA1 or SHA256 hash values (GitLab Issue).

Technical details

The vulnerability stems from an implementation gap in GitLab's security controls where tag name validation checks can be bypassed during project imports. While GitLab normally prevents the creation of tags with names matching SHA1 or SHA256 hash patterns for security purposes, this restriction could be circumvented when importing projects through various import methods including Git importer, Gitea importer, and GitLab export functionality (GitLab Issue).

Impact

The vulnerability could potentially allow attackers to manipulate code references and execute arbitrary code. If an imported pipeline from the CI/CD catalog is pinned to a commit, this vulnerability could be exploited to replace the commit with a git tag of the same name containing different code. Additionally, local code by users that rely on specific commit checkouts could be manipulated (GitLab Issue).

Mitigation and workarounds

Users should upgrade to GitLab versions 17.0.5, 17.1.3, or 17.2.1 or later, depending on their current version track. These releases include fixes for the tag name validation bypass during project imports (GitLab Issue).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12571HIGH7.5
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NoYesNov 26, 2025
CVE-2025-7449MEDIUM6.5
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesNov 26, 2025
CVE-2025-12653MEDIUM6.5
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesNov 26, 2025
CVE-2025-13611MEDIUM5.3
  • GitLabGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
NoYesNov 26, 2025
CVE-2025-6195MEDIUM4.3
  • GitLabGitLab
  • gitlab
NoYesNov 26, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management