A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-03-07 01:15
Updated : 2024-03-07 13:52
NVD link : CVE-2024-1299
Mitre link : CVE-2024-1299
CVE.ORG link : CVE-2024-1299
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization