VDB
CVE-2024-7296
CVE-2024-7296
PUBLISHED
CVSS 2.700000047683716 LOW
An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.
EPSS 0.35% · 28.1th percentile
Risk Scores
CVSS 3.1
2.700000047683716
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.35%
28.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 16.5.0 |
| Bitnami | gitlab | 16.5.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Mar 12, 2025 CVE Published
- Mar 13, 2025 CVE Updated
- Mar 14, 2025 EPSS Score
- Mar 26, 2025 Coalition ESS Score
- Mar 28, 2025 EPSS Score
- Apr 10, 2025 EPSS Score
- Apr 24, 2025 EPSS Score
- May 8, 2025 EPSS Score
- May 21, 2025 EPSS Score
- Jun 4, 2025 EPSS Score
- Jun 18, 2025 EPSS Score