CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-0410: Improper Enforcement of Behavioral Workflow in GitLab

7.7 CVSS

Description

An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

Classification

CVE ID: CVE-2024-0410

CVSS Base Severity: HIGH

CVSS Base Score: 7.7

CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Problem Types

CWE-841: Improper Enforcement of Behavioral Workflow

Affected Products

Vendor: GitLab

Product: GitLab

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.01% (probability of being exploited)

EPSS Percentile: 1.0% (scored less or equal to compared to others)

EPSS Date: 2025-06-15 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: total

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-0410
https://gitlab.com/gitlab-org/gitlab/-/issues/437988
https://hackerone.com/reports/2296778

Timeline