CVE-2024-7296

An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab/-/issues/475056 Exploit Issue Tracking
https://hackerone.com/reports/2602274 Permissions Required
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

06 Aug 2025, 18:37

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
References () https://gitlab.com/gitlab-org/gitlab/-/issues/475056 - () https://gitlab.com/gitlab-org/gitlab/-/issues/475056 - Exploit, Issue Tracking
References () https://hackerone.com/reports/2602274 - () https://hackerone.com/reports/2602274 - Permissions Required
Summary
  • (es) Se descubrió un problema en GitLab EE que afectaba a todas las versiones desde la 16.5 anterior a la 17.7.7, la 17.8 anterior a la 17.8.5 y la 17.9 anterior a la 17.9.2, que permitía que un usuario con un permiso personalizado aprobara solicitudes de membresía pendientes más allá del número máximo de usuarios permitidos.
First Time Gitlab gitlab
Gitlab

13 Mar 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-13 06:15

Updated : 2025-08-06 18:37


NVD link : CVE-2024-7296

Mitre link : CVE-2024-7296

CVE.ORG link : CVE-2024-7296


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-863

Incorrect Authorization