MEDIUM
CVE-2014-8540
CVSS
6.5
Description
The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.
Weakness (CWE)
CWE-264
Permissions, Privileges & Access Controls
EPSS Score
2.16%
Probability of exploitation in next 30 days
81.3th percentile
References
http://www.openwall.com/lists/oss-security/2014/10/31/2
Mailing List, Third Party Advisory
http://www.securityfocus.com/bid/70841
Third Party Advisory, VDB Entry
https://about.gitlab.com/2014/10/30/gitlab-7-4-3-released/
Patch, Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/98449
Third Party Advisory, VDB Entry
https://gitlab.com/gitlab-org/gitlab-ce/commit/a2dfff418bf2532ebb5aee88414107929b17eefd
Patch
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.