Description
A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner
No analysis available yet.
Remediation
Vendor Solution
Upgrade to version 16.4.4, 16.5.4 or 16.6.2
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44533 | A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows a project Maintainer to use a Project Access Token to escalate their role to Owner |
References
History
Tue, 08 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | NVD-CWE-Other |
Thu, 03 Oct 2024 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Improper Privilege Management in GitLab | Improper User Management in GitLab |
| Weaknesses | CWE-286 |
Thu, 19 Sep 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-11-20T04:08:23.279Z
Reserved: 2023-07-25T10:30:28.613Z
Link: CVE-2023-3907
Updated: 2024-08-02T07:08:50.859Z
Status : Analyzed
Published: 2023-12-17T23:15:43.937
Modified: 2025-05-05T14:14:48.773
Link: CVE-2023-3907
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD