CVE-2024-0456 PUBLISHED

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

EPSS 0.10% · 28.0th percentile

Risk Scores

EPSS Score
0.10%
28.0th percentile

Affected Products

VendorProductVersions
Bitnamigitlab14.0.0, 16.7.0, 16.8.0
Bitnamigitlab14.0.0, 16.7.0, 16.8.0

Timeline

References

Open in Interactive Console →