{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-19T12:01:54.050","vulnerabilities":[{"cve":{"id":"CVE-2024-7296","sourceIdentifier":"cve@gitlab.com","published":"2025-03-13T06:15:35.937","lastModified":"2025-08-06T18:37:18.350","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions from 16.5 prior to 17.7.7, 17.8 prior to 17.8.5, and 17.9 prior to 17.9.2  which allowed a user with a custom permission to approve pending membership requests beyond the maximum number of allowed users."},{"lang":"es","value":"Se descubrió un problema en GitLab EE que afectaba a todas las versiones desde la 16.5 anterior a la 17.7.7, la 17.8 anterior a la 17.8.5 y la 17.9 anterior a la 17.9.2, que permitía que un usuario con un permiso personalizado aprobara solicitudes de membresía pendientes más allá del número máximo de usuarios permitidos."}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N","baseScore":2.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":1.4}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"17.7.7","matchCriteriaId":"ADE71D75-7A91-46FE-808A-2B90DAB6BBC2"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.5.0","versionEndExcluding":"17.7.7","matchCriteriaId":"D24757E6-110B-423A-A85B-4DA06FF951B3"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"51278A1A-6BB1-461B-B4D0-38FD58680C3F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.8.0","versionEndExcluding":"17.8.5","matchCriteriaId":"9793DFF7-AA7F-4727-91EE-A05FB4B63D5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"257CE2B6-A495-4F46-990B-BF5D283530DA"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.2","matchCriteriaId":"6373756D-2959-4F3C-AFBA-33BB55570428"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/475056","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2602274","source":"cve@gitlab.com","tags":["Permissions Required"]}]}}]}