A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.
2024-03-07T01:15:52.443
2024-12-11T20:23:27.497
Analyzed
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 16.8.4 | Yes |
Application | gitlab | gitlab | < 16.8.4 | Yes |
Application | gitlab | gitlab | < 16.9.2 | Yes |
Application | gitlab | gitlab | < 16.9.2 | Yes |