VDB

CVE-2024-8631

CVE-2024-8631 PUBLISHED

A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.

EPSS 0.02% · 7.3th percentile

Risk Scores

EPSS Score
0.02%
7.3th percentile

Affected Products

VendorProductVersions
Bitnamigitlab16.6.0, 17.2.0, 17.3.0
Bitnamigitlab16.6.0, 17.2.0, 17.3.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Sep 11, 2024 CVE Published
  • Sep 13, 2024 EPSS Score
  • Sep 15, 2024 CVE Updated
  • Oct 3, 2024 EPSS Score
  • Oct 5, 2024 Coalition ESS Score
  • Oct 23, 2024 EPSS Score
  • Nov 11, 2024 EPSS Score
  • Dec 2, 2024 EPSS Score
  • Dec 22, 2024 EPSS Score
  • Jan 11, 2025 EPSS Score
  • Jan 30, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›