VDB

CVE-2024-0456

CVE-2024-0456 PUBLISHED CVSS 4.300000190734863 MEDIUM

An authorization vulnerability exists in GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. An unauthorized attacker is able to assign arbitrary users to MRs that they created within the project

EPSS 0.49% · 39.7th percentile

Risk Scores

CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.49%
39.7th percentile

Affected Products

VendorProductVersions
Bitnamigitlab14.0.0, 16.7.0, 16.8.0
Bitnamigitlab14.0.0, 16.7.0, 16.8.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Jan 25, 2024 CVE Published
  • Jan 26, 2024 PoC Published
  • Jan 31, 2024 EPSS Score
  • Feb 28, 2024 EPSS Score
  • Mar 27, 2024 EPSS Score
  • Apr 24, 2024 EPSS Score
  • May 21, 2024 EPSS Score
  • Jun 18, 2024 EPSS Score
  • Jul 16, 2024 EPSS Score
  • Aug 17, 2024 EPSS Score
  • Sep 14, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›