CVE-2024-1299Privilege Chaining in Gitlab

Severity
8.1HIGHNVD
EPSS
0.0%
top 94.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 7

Description

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages4 packages

CVEListV5gitlab/gitlab16.816.8.4+1
NVDgitlab/gitlab16.8.016.8.4+1
debiandebian/gitlab< gitlab 16.8.4-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-27h4-9w4j-cp97: A privilege escalation vulnerability was discovered in GitLab affecting versions 162024-03-07
OSV
CVE-2024-1299: A privilege escalation vulnerability was discovered in GitLab affecting versions 162024-03-07

📋Vendor Advisories

2
GitLab
CVE-2024-1299: A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a2024-03-07
Debian
CVE-2024-1299: gitlab - A privilege escalation vulnerability was discovered in GitLab affecting versions...2024