A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.
2024-03-07T01:15:52.443
2024-12-11T20:23:27.497
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | < 16.8.4 | Yes |
| Application | gitlab | gitlab | < 16.8.4 | Yes |
| Application | gitlab | gitlab | < 16.9.2 | Yes |
| Application | gitlab | gitlab | < 16.9.2 | Yes |