MEDIUM
CVE-2024-1250
CVSS
6.5
Description
An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.
Summary dbcve.org
In GitLab EE versions 16.8 through 16.8.1, a user assigned a custom role with the manage_group_access_tokens permission can create group access tokens that possess Owner-level privileges, allowing them to escalate their effective permissions beyond what their assigned role should permit.
Mitigation
Upgrade GitLab EE to version 16.8.2 or later which contains the fix for this privilege escalation vulnerability.
Weakness (CWE)
CWE-268
EPSS Score
0.55%
Probability of exploitation in next 30 days
44.8th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.