CVE-2024-0456

MEDIUM

GitLab <14.0-16.8.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 36.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-425
Status published
Products (5)
gitlab/gitlab 16.8.0 (2 CPE variants)
GitLab/GitLab 14.0 - 16.6.6
gitlab/gitlab 14.0.0 - 16.6.6 (2 CPE variants)
GitLab/GitLab 16.7 - 16.7.4
GitLab/GitLab 16.8 - 16.8.1
Published Jan 26, 2024
Tracked Since Feb 18, 2026