Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27h4-9w4j-cp97

Опубликовано: 07 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of manage_group_access_tokens to rotate group access tokens with owner privileges.

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of manage_group_access_tokens to rotate group access tokens with owner privileges.

EPSS

Процентиль: 2%
0.00015
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-268
CWE-863

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 1 года назад

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.

CVSS3: 6.5
nvd
больше 1 года назад

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.

CVSS3: 6.5
debian
больше 1 года назад

A privilege escalation vulnerability was discovered in GitLab affectin ...

EPSS

Процентиль: 2%
0.00015
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-268
CWE-863