Home

Description

An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.

PUBLISHED Reserved 2024-02-06 | Published 2024-02-12 | Updated 2026-05-11 | Assigner GitLab




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Problem types

CWE-268: Privilege Chaining

Product status

Default status
unaffected

16.8 (semver) before 16.8.2
affected

Credits

This vulnerability has been discovered internally by GitLab team member [Rohit Shambhuni](https://gitlab.com/rshambhuni) finder

References

gitlab.com/gitlab-org/gitlab/-/issues/439175 (GitLab Issue #439175) issue-tracking

gitlab.com/gitlab-org/gitlab/-/issues/439175 (GitLab Issue #439175) issue-tracking

cve.org (CVE-2024-1250)

nvd.nist.gov (CVE-2024-1250)

Download JSON