CVSS 3.1 Score 4.3 of 10 (medium)


Published Jan 26, 2024
Updated: Jan 31, 2024
CWE ID 285


CVE-2024-0456 is an authorization vulnerability that affects GitLab versions 14.0 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. This vulnerability allows unauthorized attackers to assign arbitrary users to merge requests (MRs) that they have created within the project. The affected products include various versions of GitLab and related components. To remediate this vulnerability, organizations should update their GitLab installations to version 16.6.6, 16.7.4, or 16.8.1, depending on the version they are currently using. This vulnerability poses a potential danger as it could allow malicious actors to gain unauthorized access and manipulate MRs in GitLab instances, potentially leading to unauthorized actions or data breaches within the organization's code repositories and projects.

Note: The information provided is based on the given data and does not include any analysis or interpretation of the severity or potential impact of the vulnerability.

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-0456 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options