MEDIUM
CVE-2023-3484
CVSS
6.5
Description
An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations.
Summary dbcve.org
An authorization bypass in GitLab EE allows authenticated attackers to modify the name or path of public top-level groups in certain situations, potentially enabling group hijacking or confusion attacks.
Mitigation
Upgrade GitLab to versions 15.11.11, 16.0.7, 16.1.2 or later. If immediate upgrade is not possible, restrict group modification permissions pending the patch.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.58%
Probability of exploitation in next 30 days
46.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.