CVE-2024-12619 MEDIUM

CVE-2024-12619: Insufficient Granularity of Access Control in GitLab

Vendor Gitlab
Product GitLab
Weakness CWE-1220
Published March 28, 2025
Last update March 28, 2025

CVSS base score

5.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality High
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N

What the vulnerability does

01Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allowing internal users to gain unauthorized access to internal projects.

Key dates

02Disclosure timeline

March 28, 2025 CVE published
March 28, 2025 Record updated