Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-1299

A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 3.6%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-1299
  • Gitlab » Gitlab » Version: 16.8.0
    cpe:2.3:a:gitlab:gitlab:16.8.0
  • Gitlab » Gitlab » Version: 16.8.1
    cpe:2.3:a:gitlab:gitlab:16.8.1
  • Gitlab » Gitlab » Version: 16.8.2
    cpe:2.3:a:gitlab:gitlab:16.8.2
  • Gitlab » Gitlab » Version: 16.8.3
    cpe:2.3:a:gitlab:gitlab:16.8.3
  • Gitlab » Gitlab » Version: 16.9.0
    cpe:2.3:a:gitlab:gitlab:16.9.0
  • Gitlab » Gitlab » Version: 16.9.1
    cpe:2.3:a:gitlab:gitlab:16.9.1


Contact Us

Shodan ® - All rights reserved