A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner
2023-12-17T23:15:43.937
2025-05-05T14:14:48.773
Analyzed
CVSSv3.1: 4.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 16.4.4 | Yes |
Application | gitlab | gitlab | < 16.5.4 | Yes |
Application | gitlab | gitlab | < 16.6.2 | Yes |