GitLab Authorization Bypass Vulnerability Affects Multiple Versions

CVE-2024-0199
7.7HIGH

Key Information

Vendor
Gitlab
Status
Gitlab
Vendor
CVE Published:
7 March 2024

Badges

đź“° News Worthy

Summary

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

Affected Version(s)

GitLab < 16.7.7

GitLab < 16.8.4

GitLab < 16.9.2

News Articles

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • First article discovered by CybersecurityNews

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database1 News Article(s)

Credit

Thanks [ali_shehab](https://hackerone.com/ali_shehab) for reporting this vulnerability through our HackerOne bug bounty program
.