CVE-2024-0861: Users with the Guest role can change Custom dashboard projects settings for projects in the victim group
An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the Guest role can change Custom dashboard projects settings contrary to permissions.
Other sources
An issue has been discovered in GitLab EE affecting all versions starting from 16.4 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. Users with the Guest role can change Custom dashboard projects settings contrary to permissions. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N, 4.3). It is now mitigated in the latest release and is assigned CVE-2024-0861.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-0861?
CVE-2024-0861 is considered a medium severity vulnerability due to the potential for unauthorized changes by users with the Guest role.
How do I fix CVE-2024-0861?
To fix CVE-2024-0861, upgrade GitLab to version 16.7.6 or 16.8.3 and later, or to any version above 16.9.1.
Who is affected by CVE-2024-0861?
CVE-2024-0861 affects all GitLab EE versions from 16.4 before 16.7.6, 16.8 before 16.8.3, and 16.9 before 16.9.1.
What types of settings can be changed due to CVE-2024-0861?
Due to CVE-2024-0861, users with the Guest role can change Custom dashboard project settings contrary to permissions.
What version of GitLab should I update to in response to CVE-2024-0861?
You should update to GitLab version 16.7.6, 16.8.3, or any version higher than 16.9.1 to mitigate CVE-2024-0861.