vulnerability
Gitlab Gitlab: CVE-2024-0199: Incorrect Authorization
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:H/Au:S/C:C/I:C/A:N) | Mar 7, 2024 | Sep 25, 2025 | Sep 25, 2025 |
Severity
7
CVSS
(AV:N/AC:H/Au:S/C:C/I:C/A:N)
Published
Mar 7, 2024
Added
Sep 25, 2025
Modified
Sep 25, 2025
Description
An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.
Solution
gitlab-gitlab-upgrade-latest
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.