CVE-2014-8540
05.01.2018, 16:29
The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.Enginsight
Vendor | Product | Version |
---|---|---|
gitlab | gitlab | 6.0.0 ≤ 𝑥 ≤ 6.9.2 |
gitlab | gitlab | 7.0.0 ≤ 𝑥 < 7.4.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References