GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*
- >= 16.6, < 18.2.7
- >= 18.3, < 18.3.3
- >= 18.4, < 18.4.1
A vulnerability exists in GitLab EE versions 16.6 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1. Project Maintainers can exploit this issue by assigning custom roles to users that grant permissions exceeding their own, thereby obtaining elevated privileges.
Exploitation of this vulnerability allows Project Maintainers to gain unauthorized elevated privileges by manipulating user roles.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.