HIGH
CVE-2023-3907
CVSS
8.8
Description
A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner
Summary dbcve.org
GitLab EE has a privilege escalation vulnerability where a project Maintainer can exploit a Project Access Token to elevate their role to Owner. This is a broken access control issue in the project's access token authorization logic.
Mitigation
Upgrade GitLab EE to versions 16.4.4, 16.5.4, 16.6.2 or later. Additionally, audit existing Project Access Tokens and maintainer-role assignments for suspicious activity.
Weakness (CWE)
CWE-286
EPSS Score
0.68%
Probability of exploitation in next 30 days
51.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.