CVE-2024-12303: Incorrect Privilege Assignment in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.
Other sources
GitLab has remediated an issue that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-12303?
CVE-2024-12303 is categorized as a high severity vulnerability due to its potential for unauthorized deletion of issues, including confidential ones.
How do I fix CVE-2024-12303?
To mitigate CVE-2024-12303, users should upgrade their GitLab CE/EE installations to version 18.0.6, 18.1.4, or 18.2.2, or later.
Which versions are affected by CVE-2024-12303?
CVE-2024-12303 affects GitLab CE/EE versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2.
Who is impacted by CVE-2024-12303?
Authenticated users with specific roles and permissions in GitLab are impacted by CVE-2024-12303.
What type of vulnerability is CVE-2024-12303?
CVE-2024-12303 is a security vulnerability that allows unauthorized deletion of issues in GitLab.