ZeroHour

CVE-2024-0199

PoC
CVSS 3.1
8.0 high
EPSS
<1%p51
Published
()
Modified
Description

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

Vendors
gitlab
Products
gitlab
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.