CRITICAL
CVE-2023-3441
CVSS
9.1
Description
An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.
Weakness (CWE)
CWE-213
EPSS Score
0.55%
Probability of exploitation in next 30 days
45.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.