vulnerability

Gitlab Gitlab: CVE-2024-0199: Incorrect Authorization

Severity
7
CVSS
(AV:N/AC:H/Au:S/C:C/I:C/A:N)
Published
Mar 7, 2024
Added
Sep 25, 2025
Modified
Sep 25, 2025

Description

An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

Solution

gitlab-gitlab-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.