An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-03-07 01:15
Updated : 2024-03-07 13:52
NVD link : CVE-2024-0199
Mitre link : CVE-2024-0199
CVE.ORG link : CVE-2024-0199
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control