MEDIUM

CVE-2023-6477

Gitlab GitLab 2024-02-22 CVSS v3.1
CVSS
6.7

Description

An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.

Summary dbcve.org

GitLab EE versions 16.5 through 16.7.6, 16.8 through 16.8.3, and 16.9 through 16.9.1 contain a privilege escalation vulnerability where users assigned a custom role with admin_group_member permission can make themselves, other members, or arbitrary users Owners of a group, bypassing intended permission boundaries.

Mitigation

Upgrade GitLab EE to versions 16.7.6, 16.8.3, 16.9.1 or later. As a compensating control, audit existing custom roles that include admin_group_member permission and restrict assignments to trusted users only.

Weakness (CWE)

CWE-266 Incorrect Privilege Assignment

EPSS Score

0.53%
Probability of exploitation in next 30 days
43.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE