Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-1299
Disclosure Date: March 07, 2024 (last updated February 26, 2025)
A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access tokens with owner privileges.
0
Attacker Value
Unknown
CVE-2024-1250
Disclosure Date: February 12, 2024 (last updated February 26, 2025)
An issue has been discovered in GitLab EE affecting all versions starting from 16.8 before 16.8.2. When a user is assigned a custom role with manage_group_access_tokens permission, they may be able to create group access tokens with Owner privileges, which may lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2023-5839
Disclosure Date: October 29, 2023 (last updated February 25, 2025)
Privilege Chaining in GitHub repository hestiacp/hestiacp prior to 1.8.9.
0
Attacker Value
Unknown
CVE-2023-20194
Disclosure Date: September 07, 2023 (last updated February 25, 2025)
A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to improper privilege management in the ERS API. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to elevate their privileges beyond the sphere of their intended access level, which would allow them to obtain sensitive information from the underlying operating system. Note: The ERS is not enabled by default. To verify the status of the ERS API in the Admin GUI, choose Administration > Settings > API Settings > API Service Settings.
0
Attacker Value
Unknown
CVE-2023-0971
Disclosure Date: June 21, 2023 (last updated February 25, 2025)
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed, remote administration of Z-Wave controllers, and S0/S2 encryption keys to be recovered.
0
Attacker Value
Unknown
CVE-2023-2250
Disclosure Date: April 24, 2023 (last updated February 24, 2025)
A flaw was found in the Open Cluster Management (OCM) when a user have access to the worker nodes which has the cluster-manager-registration-controller or cluster-manager deployments. A malicious user can take advantage of this and bind the cluster-admin to any service account or using the service account to list all secrets for all kubernetes namespaces, leading into a cluster-level privilege escalation.
0
Attacker Value
Unknown
CVE-2023-0759
Disclosure Date: February 09, 2023 (last updated February 24, 2025)
Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8.
0
Attacker Value
Unknown
CVE-2022-1003
Disclosure Date: March 18, 2022 (last updated February 23, 2025)
One of the API in Mattermost version 6.3.0 and earlier fails to properly protect the permissions, which allows the system administrators to combine the two distinct privileges/capabilities in a way that allows them to override certain restricted configurations like EnableUploads.
0