CVE-2024-12431

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

05 Aug 2025, 15:25

Type Values Removed Values Added
First Time Gitlab gitlab
Gitlab
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
References () https://hackerone.com/reports/2877710 - () https://hackerone.com/reports/2877710 - Permissions Required
References () https://gitlab.com/gitlab-org/gitlab/-/issues/508742 - () https://gitlab.com/gitlab-org/gitlab/-/issues/508742 - Exploit, Issue Tracking
References () https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#unauthorized-user-can-manipulate-status-of-issues-in-public-projects - () https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#unauthorized-user-can-manipulate-status-of-issues-in-public-projects - Release Notes, Vendor Advisory

08 Jan 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-08 21:15

Updated : 2025-08-05 15:25


NVD link : CVE-2024-12431

Mitre link : CVE-2024-12431


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-862

Missing Authorization