An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Jan 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects. | |
Title | Missing Authorization in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-862 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2025-01-08T20:30:42.896Z
Updated: 2025-01-08T20:30:42.896Z
Reserved: 2024-12-10T17:02:00.858Z
Link: CVE-2024-12431
Vulnrichment
No data.
NVD
Status : Received
Published: 2025-01-08T21:15:11.760
Modified: 2025-01-08T21:15:11.760
Link: CVE-2024-12431
Redhat
No data.