CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-8631

High Severity
Gitlab
SVRS
66/100

CVSSv3
7.2/10

EPSS
0.00012/1

CVE-2024-8631: GitLab Privilege Escalation Vulnerability. This CVE describes a critical security flaw in GitLab EE where a user with the Admin Group Member custom role could escalate their privileges. Affected versions include all versions from 16.6 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. With a CVSS score of 7.2 and a SOCRadar Vulnerability Risk Score (SVRS) of 66, this vulnerability requires attention. Although the SVRS is not in the critical range (above 80), the potential for unauthorized access and control within GitLab instances makes it a significant risk. Applying the security patches is crucial. This exploit being "In The Wild" further amplifies the urgency, as it indicates active exploitation attempts. Organizations using GitLab should prioritize patching to mitigate potential threats and maintain the integrity of their systems.

In The Wild
CVSS:3.1
AV:N
AC:L
PR:H
UI:N
S:U
C:H
I:H
A:H
2024-09-12

2024-09-14

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

GitLab Critical Patch Release: 17.3.2, 17.2.5, 17.1.7
Ottilia Westerlund2025-04-01
GitLab Critical Patch Release: 17.3.2, 17.2.5, 17.1.7 | Today we are releasing versions 17.3.2, 17.2.5, 17.1.7 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for
news
gitlab.com
rss
forum

Social Media

CVE-2024-8631 (CVSS:7.2, HIGH) is Analyzed. A privilege escalation issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.1.7,..https://t.co/pdc2ZJAUEM #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppGitlabgitlab

References

ReferenceLink
[email protected]https://gitlab.com/gitlab-org/gitlab/-/issues/462665
[email protected]https://hackerone.com/reports/2478469
GITHUBhttps://gitlab.com/gitlab-org/gitlab/-/issues/462665

CWE Details

CWE IDCWE NameDescription
CWE-267Privilege Defined With Unsafe ActionsA particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence