CVE Vulnerabilities

CVE-2024-1299

Privilege Chaining

Published: Mar 07, 2024 | Modified: Dec 11, 2024
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of manage_group_access_tokens to rotate group access tokens with owner privileges.

Weakness

Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 16.8.0 (including) 16.8.4 (excluding)
Gitlab Gitlab 16.9.0 (including) 16.9.2 (excluding)
Gitlab Ubuntu esm-apps/xenial *

Potential Mitigations

References