CVE-2024-8631

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 09:53

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 5.5
References
  • () https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/ -

14 Sep 2024, 15:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 7.2
CWE NVD-CWE-noinfo
Summary
  • (es) Se ha descubierto un problema de escalada de privilegios en GitLab EE que afecta a todas las versiones a partir de la 16.6 anterior a la 17.1.7, de la 17.2 anterior a la 17.2.5 y de la 17.3 anterior a la 17.3.2. Un usuario al que se le haya asignado el rol personalizado de Miembro del grupo de administradores podría haber escalado sus privilegios para incluir otros roles personalizados.
First Time Gitlab
Gitlab gitlab
References () https://gitlab.com/gitlab-org/gitlab/-/issues/462665 - () https://gitlab.com/gitlab-org/gitlab/-/issues/462665 - Broken Link
References () https://hackerone.com/reports/2478469 - () https://hackerone.com/reports/2478469 - Permissions Required
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

12 Sep 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-12 17:15

Updated : 2024-11-21 09:53


NVD link : CVE-2024-8631

Mitre link : CVE-2024-8631

CVE.ORG link : CVE-2024-8631


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-267

Privilege Defined With Unsafe Actions

NVD-CWE-noinfo