MEDIUM

CVE-2014-8540

Gitlab GitLab 2018-01-05 CVSS v3.0
CVSS
6.5

Description

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.

Weakness (CWE)

CWE-264 Permissions, Privileges & Access Controls

EPSS Score

2.16%
Probability of exploitation in next 30 days
81.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE