CVE-2024-0199

HIGH

Gitlab < 16.7.7 - Incorrect Authorization

Title source: rule

Description

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

Scores

CVSS v3 7.7
EPSS 0.0001
EPSS Percentile 0.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Classification

CWE
CWE-863
Status published

Affected Products (2)

gitlab/gitlab < 16.7.7
gitlab/gitlab < 16.7.7

Timeline

Published Mar 07, 2024
Tracked Since Feb 18, 2026