CVE Vulnerabilities

CVE-2023-2485

Incorrect Privilege Assignment

Published: Jun 07, 2023 | Modified: Mar 20, 2025
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A malicious maintainer in a project can escalate other users to Owners in that project if they import members from another project that those other users are Owners of.

Weakness

A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab14.1.0 (including)15.10.8 (excluding)
GitlabGitlab15.11.0 (including)15.11.7 (excluding)
GitlabGitlab16.0.0 (including)16.0.2 (excluding)
GitlabUbuntubionic*
GitlabUbuntuesm-apps/xenial*
GitlabUbuntutrusty*
GitlabUbuntuxenial*

Potential Mitigations

References