MEDIUM

CVE-2024-12303

Gitlab GitLab 2025-08-13 CVSS v3.1
CVSS
5.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

Summary dbcve.org

This is an authorization bypass vulnerability in GitLab where authenticated users with specific roles can delete issues (including confidential ones) they shouldn't have access to by exploiting the user invitation functionality with a specific role. The vulnerability stems from improper validation of permissions when processing invitations combined with issue deletion rights.

Mitigation

Upgrade GitLab to version 18.0.6, 18.1.4, or 18.2.2 or later. For environments that cannot upgrade immediately, review user role assignments and invitation settings to limit the combination of permissions that enables this attack vector.

Weakness (CWE)

CWE-266 Incorrect Privilege Assignment

EPSS Score

0.4%
Probability of exploitation in next 30 days
34.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE