CVE Vulnerabilities

CVE-2024-8631

Published: Sep 12, 2024 | Modified: Sep 14, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 16.6.0 (including) 17.1.7 (excluding)
Gitlab Gitlab 17.2.0 (including) 17.2.5 (excluding)
Gitlab Gitlab 17.3.0 (including) 17.3.2 (excluding)

References