CVE-2023-2182Improper Privilege Management in Gitlab

5 documents5 sources
Severity
8.8HIGHNVD
EPSS
0.4%
top 39.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 3
Latest updateDec 8

Description

An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. Under certain conditions when OpenID Connect is enabled on an instance, it may allow users who are marked as 'external' to become 'regular' users thus leading to privilege escalation for those users.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

NVDgitlab/gitlab15.10.015.10.5+1
CVEListV5gitlab/gitlab>=15.10, <15.10.5, >=15.11, <15.11.1+1
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-j24v-67h6-cx49: An issue has been discovered in GitLab EE affecting all versions starting from 152023-05-04

📋Vendor Advisories

2
GitLab
CVE-2023-2182: An issue has been discovered in GitLab EE affecting all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1.2023-05-03
Debian
CVE-2023-2182: gitlab - An issue has been discovered in GitLab EE affecting all versions starting from 1...2023

📄Research Papers

1
arXiv
A Red Teaming Framework for Securing AI in Maritime Autonomous Systems2023-12-08