Security Advisory

CVE-2024-5258

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-05-23 11:02:06
Last updated 2024-08-29 15:04:59
Assigner GitLab
State PUBLISHED

Description

An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1 where an authenticated attacker could utilize a crafted naming convention to bypass pipeline authorization logic.