VulnerabilityModified
CVE-2024-0456
An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1.
MEDIUM 4.3EPSS 0.49%
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-425
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/430726Broken Link
- https://about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/430726Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.