CVE-2024-8631: Privilege Defined With Unsafe Actions in GitLab
A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. A user assigned the Admin Group Member custom role could have escalated their privileges to include other custom roles.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8631?
CVE-2024-8631 is classified as a privilege escalation vulnerability in GitLab EE.
How do I fix CVE-2024-8631?
To fix CVE-2024-8631, upgrade GitLab to version 17.1.7, 17.2.5, or 17.3.2 or later.
What versions of GitLab are affected by CVE-2024-8631?
CVE-2024-8631 affects GitLab EE versions from 16.6 prior to 17.1.7, 17.2 prior to 17.2.5, and 17.3 prior to 17.3.2.
What types of users are impacted by CVE-2024-8631?
Users assigned the Admin Group Member custom role are specifically impacted by CVE-2024-8631.
Is there a workaround for CVE-2024-8631?
There is no official workaround for CVE-2024-8631; updating to a secure version is recommended.