CVE-2014-8540: GitLab

Medium severity, CVSS 6.5. EPSS: 2.2% chance of exploitation in the next 30 days.

The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.

Affected products

  • GitLab GitLab: from 6.0.0, up to and including 6.9.2; from 7.0.0, before 7.4.3 (fixed in 7.4.3)

Published 2018-01-05. Last modified 2026-06-17.