Overview
- Description
- An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. When a user is assigned a custom role with admin_group_member permission, they may be able to make a group, other members or themselves Owners of that group, which may lead to privilege escalation.
- Source
- cve@gitlab.com
- NVD status
- Modified
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.7
- Impact score
- 5.5
- Exploitability score
- 1.2
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
- Severity
- MEDIUM
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
- cve@gitlab.com
- CWE-266
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "B2558C81-DADC-475C-A06B-DB9048CE85FC", "versionEndExcluding": "16.7.6", "versionStartIncluding": "16.5.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "BF18D8E8-7406-46F4-BDDD-CC743A5C4D80", "versionEndIncluding": "16.8.3", "versionStartIncluding": "16.8.0" }, { "criteria": "cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:enterprise:*:*:*", "vulnerable": true, "matchCriteriaId": "1E374890-90FC-4DC5-8C0B-87CC99B4A4D7" } ], "operator": "OR" } ] } ]