The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.
CVSS v3.0 Score
6.5
/ 10.0
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Information
- Published
- 5 janv. 2018
- Updated
- 21 nov. 2024
- Status
- Modified
- Source
- cve@mitre.org
Affected products
gitlab gitlab
Versions : 6.9.2, 7.4.3
Weaknesses (CWE)
CWE-264
References (10)
- http://www.openwall.com/lists/oss-security/2014/10/31/2Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/70841Third Party AdvisoryVDB Entry
- https://about.gitlab.com/2014/10/30/gitlab-7-4-3-released/PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98449Third Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2014/10/31/2Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/70841Third Party AdvisoryVDB Entry
- https://about.gitlab.com/2014/10/30/gitlab-7-4-3-released/PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/98449Third Party AdvisoryVDB Entry
Similar CVEs
Other vulnerabilities of type CWE-264
Loading…
Monitor your products
Get automatic alerts for every new CVE affecting your equipment.