CVE-2024-0199

HIGH

GitLab 11.3-16.7.6 16.8.3-16.8.3 - Incorrect Authorization Bypass via Crafted Payload in Old Feature Branch

Title source: llm
STIX 2.1

Description

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

References (3)

Core 3
Core References
Exploit, Issue Tracking issue-tracking permissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/436977
Permissions Required technical-description exploit permissions-required
https://hackerone.com/reports/2295423

Scores

CVSS v3 7.7
EPSS 0.0001
EPSS Percentile 0.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
gitlab/gitlab 11.3 - 16.7.7 (2 CPE variants)
Published Mar 07, 2024
Tracked Since Feb 18, 2026