MEDIUM
Incorrect Privilege Assignment in GitLab
Published Feb 21, 2024
6.7
MEDIUMCVSS 3.1
EPSS 0.53%
Description
An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.
Affected products
-
- Version 16.5StatusaffectedConstraints<16.7.6
- Version 16.8StatusaffectedConstraints<16.8.3
- Version 16.9StatusaffectedConstraints<16.9.1
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 16.9.1, 16.8.3, 16.7.6 or above.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58710 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/433463 issue-trackingpermissions-requiredPermissions Required
- https://hackerone.com/reports/2270898 technical-descriptionexploitpermissions-requiredPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-58710 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/433463 | issue-trackingpermissions-requiredPermissions Required | |
| https://hackerone.com/reports/2270898 | technical-descriptionexploitpermissions-requiredPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Feb 21, 2024
Updated May 15, 2026
Reserved Dec 4, 2023
Link CVE-2023-6477
CISA Vulnrichment
Updated Feb 22, 2024
ENISA EUVD
EUVD-2023-58710 Assigner GitLab
Published Feb 21, 2024
Updated May 15, 2026
Exploited since n/a
Link EUVD-2023-58710