Back

LOW

Incorrect Authorization in GitLab

Published Mar 13, 2025

Description

An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2 which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users.

Affected products

Remediation

Vendor solution

Upgrade to versions 17.7.7, 17.8.5, 17.9.2 or above.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Mar 13, 2025
Updated Mar 14, 2025
Reserved Jul 30, 2024
CISA Vulnrichment
Updated Mar 14, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a