CVE-2024-1299

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/03/2024
Last modified:
11/12/2024

Description

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 16.8.0 (including) 16.8.4 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 16.8.0 (including) 16.8.4 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* 16.9.0 (including) 16.9.2 (excluding)
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* 16.9.0 (including) 16.9.2 (excluding)