CVE-2023-4700
Description
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.
Summary dbcve.org
This is an authorization bypass vulnerability in GitLab Enterprise Edition where users can execute CI/CD jobs in protected environments without the required approval checks. Protected environments in GitLab are designed to have mandatory approval workflows for deployments to sensitive targets, but this flaw allowed authenticated users to circumvent those safeguards.
Mitigation
Upgrade GitLab to version 16.3.6, 16.4.2, 16.5.1 or later to receive the security patch. After upgrading, verify that protected environment approval workflows are functioning correctly.