The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | 6.0.0 (including) | 6.9.2 (including) |
Gitlab | Gitlab | 7.0.0 (including) | 7.4.3 (excluding) |