CVE-2024-12431Missing Authorization in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.1%
top 70.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5gitlab/gitlab15.517.5.5+2
NVDgitlab/gitlab15.5.017.5.5+2
debiandebian/gitlab< gitlab 17.5.5-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-hjr5-q2v6-7chx: An issue was discovered in GitLab CE/EE affecting all versions starting from 152025-01-08
OSV
CVE-2024-12431: An issue was discovered in GitLab CE/EE affecting all versions starting from 152025-01-08

📋Vendor Advisories

2
GitLab
CVE-2024-12431: An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which2025-01-08
Debian
CVE-2024-12431: gitlab - An issue was discovered in GitLab CE/EE affecting all versions starting from 15....2024