CVE-2024-7296
CVSS 3.1 Score 2.7 of 10 (low)
Details
Published Mar 13, 2025
CWE ID 863
Summary
CVE-2024-7296 is a vulnerability affecting GitLab Enterprise Edition (EE). This issue, which exists in versions 16.5 to 17.9, allows a user with custom permissions to approve an excessive number of pending membership requests, surpassing the maximum limit. This can potentially lead to unintended access to the GitLab project or team. The vulnerability impacts versions 17.7.7 and later for 17.7, 17.8.5 and later for 17.8, and 17.9.2 and later for 17.9. GitLab urges users to upgrade to the latest versions to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
Affected Vendors
- GitLab Inc.