HIGH
CVE-2024-8114
CVSS
8.8
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.
Summary dbcve.org
This GitLab vulnerability allows an attacker who obtains a victim's Personal Access Token (PAT) to perform privilege escalation, potentially gaining higher-level permissions than the token originally possessed. The specific technical mechanism (injection, validation bypass, etc.) is not detailed in the available advisory.
Mitigation
Upgrade GitLab to version 17.4.5, 17.5.3, 17.6.1 or later. Additionally, revoke potentially compromised PATs and review token permissions and audit logs for suspicious activity.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.67%
Probability of exploitation in next 30 days
50.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.