HIGH

CVE-2024-8631

Gitlab GitLab 2024-09-12 CVSS v3.1
CVSS
7.2

Description

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.

Summary dbcve.org

GitLab EE versions prior to 17.1.7, 17.2.5, and 17.3.2 contain a privilege escalation vulnerability where users assigned the Admin Group Member custom role can escalate their privileges to include other custom roles they should not have access to.

Mitigation

Upgrade GitLab EE to version 17.1.7, 17.2.5, or 17.3.2 or later to remediate this vulnerability.

Weakness (CWE)

CWE-267

EPSS Score

0.52%
Probability of exploitation in next 30 days
43.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE