CVE-2024-43409: Ghost's improper authentication allows access to member information and actions
(updated )
Improper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.
References
Detect and mitigate CVE-2024-43409 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →