VDB

CVE-2024-7296

CVE-2024-7296 PUBLISHED CVSS 2.700000047683716 LOW

An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.

EPSS 0.35% · 28.1th percentile

Risk Scores

CVSS 3.1
2.700000047683716
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.35%
28.1th percentile

Affected Products

VendorProductVersions
Bitnamigitlab16.5.0
Bitnamigitlab16.5.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Mar 12, 2025 CVE Published
  • Mar 13, 2025 CVE Updated
  • Mar 14, 2025 EPSS Score
  • Mar 26, 2025 Coalition ESS Score
  • Mar 28, 2025 EPSS Score
  • Apr 10, 2025 EPSS Score
  • Apr 24, 2025 EPSS Score
  • May 8, 2025 EPSS Score
  • May 21, 2025 EPSS Score
  • Jun 4, 2025 EPSS Score
  • Jun 18, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›