HIGH

CVE-2024-0410

Gitlab GitLab 2024-02-22 CVSS v3.1
CVSS
7.7

Description

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

Summary dbcve.org

This is an authorization bypass vulnerability in GitLab where a developer can circumvent CODEOWNERS approval requirements by creating a merge conflict. CODEOWNERS is a feature that enforces mandatory review/approval from designated owners for certain file paths, but the vulnerability allows attackers to bypass this security control.

Mitigation

Upgrade GitLab to versions 16.7.6, 16.8.3, 16.9.1 or later. This is a standard patch upgrade following GitLab's documented upgrade path.

Weakness (CWE)

CWE-841

EPSS Score

0.46%
Probability of exploitation in next 30 days
39.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE