CVE-2024-12303
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.
Summary dbcve.org
This is an authorization bypass vulnerability in GitLab where authenticated users with specific roles can delete issues (including confidential ones) they shouldn't have access to by exploiting the user invitation functionality with a specific role. The vulnerability stems from improper validation of permissions when processing invitations combined with issue deletion rights.
Mitigation
Upgrade GitLab to version 18.0.6, 18.1.4, or 18.2.2 or later. For environments that cannot upgrade immediately, review user role assignments and invitation settings to limit the combination of permissions that enables this attack vector.