CVE-2024-1250
CVSS V2 None
CVSS V3 None
Description
An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.
Overview
- CVE ID
- CVE-2024-1250
- Assigner
- GitLab
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-02-12T20:47:44.401Z
- Last Modified Date
- 2024-03-13T04:04:49.939Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/439175 | issue-tracking |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-1250 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1250 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 06:04:40 | Added to TrackCVE |