HIGH

CVE-2024-8114

Gitlab GitLab 2024-11-26 CVSS v3.1
CVSS
8.8

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

Summary dbcve.org

This GitLab vulnerability allows an attacker who obtains a victim's Personal Access Token (PAT) to perform privilege escalation, potentially gaining higher-level permissions than the token originally possessed. The specific technical mechanism (injection, validation bypass, etc.) is not detailed in the available advisory.

Mitigation

Upgrade GitLab to version 17.4.5, 17.5.3, 17.6.1 or later. Additionally, revoke potentially compromised PATs and review token permissions and audit logs for suspicious activity.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.67%
Probability of exploitation in next 30 days
50.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE