CVE-2024-5258

CVSS V2 None CVSS V3 None
Description
An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.
Overview
  • CVE ID
  • CVE-2024-5258
  • Assigner
  • GitLab
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-23T11:02:06.904Z
  • Last Modified Date
  • 2024-06-04T18:01:51.492Z
References
Reference URL Reference Tags
https://gitlab.com/gitlab-org/gitlab/-/issues/443254 issue-tracking permissions-required
History
Created Old Value New Value Data Type Notes
2024-06-26 03:29:13 Added to TrackCVE