CVE-2024-6356
MEDIUMDescription
An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.
Is your site exposed to CVE-2024-6356?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| gitlab | gitlab |
| gitlab | gitlab |
| gitlab | gitlab |
References
Other References
Frequently Asked Questions
What is CVE-2024-6356? +
How severe is CVE-2024-6356? +
What products are affected by CVE-2024-6356? +
How do I check if I'm vulnerable to CVE-2024-6356? +
Related Vulnerabilities
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened …
A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable …
An escalation of privilege vulnerability in ASPECT could provide an attacker root access to a server when logged in as …
phpMyFAQ is an open source FAQ web application. Versions 4.0-nightly-2025-10-03 and below do not enforce uniqueness of email addresses during …
The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. …