MEDIUM
CVE-2023-2181
CVSS
6.5
Description
An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.
Summary dbcve.org
A malicious developer can exploit git's refs/replace feature to smuggle hidden content into a merge request that is invisible during UI-based code review, effectively bypassing the code review process. This allows un-reviewed or malicious code to be merged without reviewers seeing the actual changes.
Mitigation
Upgrade GitLab to version 15.9.8, 15.10.7, or 15.11.3 or later to patch this code review bypass vulnerability.
EPSS Score
0.73%
Probability of exploitation in next 30 days
52.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.