CVE-2024-2880: Improper Access Control in GitLab
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with admingroupmember custom role permission could ban group members.
Other sources
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.5 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 in which a user with admingroupmember custom role permission could ban group members. This is a low severity issue (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N, 2.7). It is now mitigated in the latest release and is assigned CVE-2024-2880.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-2880?
CVE-2024-2880 has a severity that may vary but is concerning due to its impact on group member management.
Who is affected by CVE-2024-2880?
CVE-2024-2880 affects GitLab CE/EE versions starting from 16.5 to prior 16.11.6, 17.0 to prior 17.0.4, and 17.1 to prior 17.1.2.
How do I fix CVE-2024-2880?
To fix CVE-2024-2880, update GitLab CE/EE to the latest version that is not affected by this vulnerability.
What does CVE-2024-2880 allow a user to do?
CVE-2024-2880 allows a user with `admin_group_member` custom role permission to ban group members.
Is it safe to use vulnerable versions of GitLab with CVE-2024-2880?
It is not safe to use vulnerable versions of GitLab with CVE-2024-2880 as this vulnerability potentially allows unauthorized management of group memberships.