CVE-2024-39690: Capsule tenant owner with "patch namespace" permission can hijack system namespaces
The tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), thereby gaining control of that namespace.
I would like to express my apologies once again. I have always been sincere in my research and communication, and I did not intend to disturb you on purpose.
References
Detect and mitigate CVE-2024-39690 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →