NA

CVE-2024-1250

Published: 12/02/2024 Updated: 04/03/2024
CVSS v3 Base Score: 6.5 | Impact Score: 5.2 | Exploitability Score: 1.2
VMScore: 0

Vulnerability Summary

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 prior to 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab