An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.
Fixes

Solution

Upgrade to versions 17.1.1, 17.0.3, 16.11.5 or above.


Workaround

No workaround given by the vendor.

History

Thu, 09 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Aug 2024 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2025-01-09T21:38:32.388Z

Reserved: 2024-04-19T17:30:41.875Z

Link: CVE-2024-4011

cve-icon Vulnrichment

Updated: 2024-08-01T20:26:57.321Z

cve-icon NVD

Status : Modified

Published: 2024-06-27T00:15:11.643

Modified: 2024-11-21T09:42:01.843

Link: CVE-2024-4011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.