A privilege escalation vulnerability was discovered in...
Moderate severity
Unreviewed
Published
Mar 7, 2024
to the GitHub Advisory Database
•
Updated Oct 3, 2024
Description
Published by the National Vulnerability Database
Mar 7, 2024
Published to the GitHub Advisory Database
Mar 7, 2024
Last updated
Oct 3, 2024
A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of
manage_group_access_tokens
to rotate group access tokens with owner privileges.References