An issue has been discovered in GitLab EE affecting all versions starting from 16.1 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. If an external user is given an owner role on any group, that external user may escalate their privileges on the instance by creating a service account in that group. This service account is not classified as external and may be used to access internal projects.
Metrics
Affected Vendors & Products
References
History
Thu, 19 Sep 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2023-09-01T10:01:16.853Z
Updated: 2024-09-18T04:05:50.196Z
Reserved: 2023-07-25T10:30:31.836Z
Link: CVE-2023-3915
Vulnrichment
Updated: 2024-08-02T07:08:50.788Z
NVD
Status : Modified
Published: 2023-09-01T11:15:42.267
Modified: 2024-11-21T08:18:20.367
Link: CVE-2023-3915
Redhat
No data.