PT-2024-6746 · Gitlab · Gitlab Ce/Ee+1

Ashish

+1

·

Published

2024-04-19

·

Updated

2024-08-30

·

CVE-2024-4011

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions 16.1 through 16.11.5 GitLab CE/EE versions 17.0 through 17.0.3 GitLab CE/EE versions 17.1 through 17.1.1
Description: The issue is related to inadequate access control in GitLab, a collaborative coding platform. It allows a non-project member to promote key results to objectives, potentially leading to unauthorized access to protected information.
Recommendations: For versions 16.1 through 16.11.5, update to version 16.11.5 or later. For versions 17.0 through 17.0.3, update to version 17.0.3 or later. For versions 17.1 through 17.1.1, update to version 17.1.1 or later.

Exploit

Fix

Improper Access Control

Improper Privilege Management

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-07959
BIT-GITLAB-2024-4011
CVE-2024-4011

Affected Products

Gitlab
Gitlab Ce/Ee