Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-12303


An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.


Published

2025-08-13T18:15:28.573

Last Modified

2025-08-15T16:24:44.060

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-266

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 18.0.6 Yes
Application gitlab gitlab < 18.0.6 Yes
Application gitlab gitlab < 18.1.4 Yes
Application gitlab gitlab < 18.1.4 Yes
Application gitlab gitlab < 18.2.2 Yes
Application gitlab gitlab < 18.2.2 Yes

References