GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: authenticated user can obtain higher-privileged users' credentials and act as them

CVSS 6.4CVE-2024-9183Control plane, storage & DevOpscurated

Impact

Under conditions GitLab does not detail publicly, an authenticated user could obtain credentials belonging to higher-privileged users and then perform actions in their context. For a datacenter that runs GitLab as its CI/CD and GitOps source of truth, that is a privilege escalation into the pipelines that build images and deploy to the fleet, so the blast radius is whatever those higher-privileged accounts can push or deploy. GitLab rates confidentiality and integrity high; exploitation needs user interaction and is rated high complexity. The record gives no mechanism beyond that, so treat the exposure as credential theft within the GitLab instance rather than a specific remote code path.

Who can reach it

An authenticated GitLab user on the instance, plus interaction from a higher-privileged victim user. No pre-existing elevated access is required.

What to do

Upgrade to GitLab 18.4.5, 18.5.3 or 18.6.1 depending on your branch and restart the GitLab services - a single-instance maintenance window, no fleet impact. Rotate tokens and credentials for administrator and maintainer accounts if you suspect exposure, since the flaw yields credentials rather than a session.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.