PT-2024-15575 · Gitlab · Gitlab

Niklas Van Schrick

·

Published

2024-01-25

·

Updated

2024-10-03

·

CVE-2024-0456

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 14.0 through 16.6.5 GitLab versions 16.7 through 16.7.3 GitLab versions 16.8 through 16.8.0
Description An authorization issue exists, allowing an unauthorized attacker to assign arbitrary users to merge requests (MRs) they created within a project.
Recommendations For versions 14.0 through 16.6.5, update to version 16.6.6 or later. For versions 16.7 through 16.7.3, update to version 16.7.4 or later. For versions 16.8 through 16.8.0, update to version 16.8.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2024-0456
CVE-2024-0456

Affected Products

Gitlab