Back to search

CVE-2014-8540

MEDIUM
6.5NVD

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.

Share:

CVSS v3.0 Score

6.5
/ 10.0
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Information

Published
5 janv. 2018
Updated
21 nov. 2024
Status
Modified
Source
cve@mitre.org

Affected products

gitlab gitlab
Versions : 6.9.2, 7.4.3

Weaknesses (CWE)

CWE-264

Similar CVEs

Other vulnerabilities of type CWE-264

Loading…

Monitor your products

Get automatic alerts for every new CVE affecting your equipment.

Enable monitoring