CVE-2023-6477
Description
An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.
Summary dbcve.org
GitLab EE versions 16.5 through 16.7.6, 16.8 through 16.8.3, and 16.9 through 16.9.1 contain a privilege escalation vulnerability where users assigned a custom role with admin_group_member permission can make themselves, other members, or arbitrary users Owners of a group, bypassing intended permission boundaries.
Mitigation
Upgrade GitLab EE to versions 16.7.6, 16.8.3, 16.9.1 or later. As a compensating control, audit existing custom roles that include admin_group_member permission and restrict assignments to trusted users only.