GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 16.10, < 17.11.5
- >= 18.0, < 18.0.3
- >= 18.1, < 18.1.1
A vulnerability exists in GitLab EE versions 16.10 prior to 17.11.5, 18.0 prior to 18.0.3, and 18.1 prior to 18.1.1. This issue could have allowed authenticated users to improperly assign compliance frameworks to projects. The vulnerability arose from the ability to send manipulated GraphQL mutations that circumvented permission checks specific to the frameworks.
Exploitation of this vulnerability could lead to improper assignment of compliance frameworks, allowing users to assign unrelated frameworks to projects without the necessary permissions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.