CVE-2024-12303

Incorrect Privilege Assignment issue in delete issues operation impacts GitLab CE/EE

GitLab CE/EE における Issue 削除の権限制御不備

GitLab has remediated an issue that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones by inviting users with a specific role.

Disclosure Date

2024/12/03

Credit

Yuki Osaki

Reference