Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9396-6m54-w269

Опубликовано: 26 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 3.8

Описание

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges.

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges.

EPSS

Процентиль: 3%
0.00016
Низкий

3.8 Low

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 3.8
nvd
4 месяца назад

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maintainers can exploit a vulnerability where they can assign custom roles to users with permissions exceeding their own, effectively granting themselves elevated privileges.

CVSS3: 3.8
debian
4 месяца назад

An issue has been discovered in GitLab EE affecting all versions from ...

EPSS

Процентиль: 3%
0.00016
Низкий

3.8 Low

CVSS3

Дефекты

CWE-862