MEDIUM

CVE-2024-1250

Gitlab GitLab 2024-02-12 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

Summary dbcve.org

In GitLab EE versions 16.8 through 16.8.1, a user assigned a custom role with the manage_group_access_tokens permission can create group access tokens that possess Owner-level privileges, allowing them to escalate their effective permissions beyond what their assigned role should permit.

Mitigation

Upgrade GitLab EE to version 16.8.2 or later which contains the fix for this privilege escalation vulnerability.

Weakness (CWE)

CWE-268

EPSS Score

0.55%
Probability of exploitation in next 30 days
44.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE