Loading HuntDB...

GHSA-fh7h-m5x3-9v4g

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. If a group with SAML SSO enabled is transferred to a new namespace as a child group, it's possible previously removed malicious maintainer or owner of the child group can still gain access to the group via SSO or a SCIM token to perform actions on the group.

Related CVEs

Key Information

GHSA ID
GHSA-fh7h-m5x3-9v4g
Published
March 10, 2023 12:30 AM
Last Modified
March 15, 2023 6:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 16, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.