PT-2024-1871 · Gitlab · Gitlab
Ali_Shehab
·
Published
2024-01-11
·
Updated
2024-10-03
·
CVE-2024-0410
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab versions 15.1 through 16.7.5
GitLab versions 16.8 through 16.8.2
GitLab versions 16.9 through 16.9.0
Description
The issue is related to insufficient access control in GitLab, allowing a remote attacker to bypass security restrictions. A developer can bypass CODEOWNERS approvals by creating a merge conflict.
Recommendations
For GitLab versions 15.1 through 16.7.5, update to version 16.7.6 or later.
For GitLab versions 16.8 through 16.8.2, update to version 16.8.3 or later.
For GitLab versions 16.9 through 16.9.0, update to version 16.9.1 or later.
As a temporary workaround, consider restricting the ability to create merge conflicts until a patch is available.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab