HIGH

CVE-2023-3907

Gitlab GitLab 2023-12-17 CVSS v3.1
CVSS
8.8

Description

A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner

Summary dbcve.org

GitLab EE has a privilege escalation vulnerability where a project Maintainer can exploit a Project Access Token to elevate their role to Owner. This is a broken access control issue in the project's access token authorization logic.

Mitigation

Upgrade GitLab EE to versions 16.4.4, 16.5.4, 16.6.2 or later. Additionally, audit existing Project Access Tokens and maintainer-role assignments for suspicious activity.

Weakness (CWE)

CWE-286

EPSS Score

0.68%
Probability of exploitation in next 30 days
51.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE