MEDIUM

CVE-2023-3484

Gitlab GitLab 2023-07-21 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain situations.

Summary dbcve.org

An authorization bypass in GitLab EE allows authenticated attackers to modify the name or path of public top-level groups in certain situations, potentially enabling group hijacking or confusion attacks.

Mitigation

Upgrade GitLab to versions 15.11.11, 16.0.7, 16.1.2 or later. If immediate upgrade is not possible, restrict group modification permissions pending the patch.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.58%
Probability of exploitation in next 30 days
46.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE