CVE-2014-8540

Publication date

2018-01-05 16:00:00

Family

mitre

State

PUBLISHED

Description

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.