CVE-2024-0199
HIGHGitlab < 16.7.7 - Incorrect Authorization
Title source: ruleDescription
An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.
Scores
CVSS v3
7.7
EPSS
0.0001
EPSS Percentile
0.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Classification
CWE
CWE-863
Status
published
Affected Products (2)
gitlab/gitlab
< 16.7.7
gitlab/gitlab
< 16.7.7
Timeline
Published
Mar 07, 2024
Tracked Since
Feb 18, 2026