VulnerabilityAnalyzed
CVE-2024-0199
An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2.
HIGH 8.0EPSS 0.71%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.
- CVSS 3.1
- 8.0 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.71% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://about.gitlab.com/releases/2024/03/06/security-release-gitlab-16-9-2-released/Release Notes
- https://gitlab.com/gitlab-org/gitlab/-/issues/436977Exploit, Issue Tracking
- https://hackerone.com/reports/2295423Permissions Required
- https://about.gitlab.com/releases/2024/03/06/security-release-gitlab-16-9-2-released/Release Notes
- https://gitlab.com/gitlab-org/gitlab/-/issues/436977Exploit, Issue Tracking
- https://hackerone.com/reports/2295423Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.