MEDIUM

CVE-2023-4700

Gitlab GitLab 2023-11-06 CVSS v3.1
CVSS
6.5

Description

An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.

Summary dbcve.org

This is an authorization bypass vulnerability in GitLab Enterprise Edition where users can execute CI/CD jobs in protected environments without the required approval checks. Protected environments in GitLab are designed to have mandatory approval workflows for deployments to sensitive targets, but this flaw allowed authenticated users to circumvent those safeguards.

Mitigation

Upgrade GitLab to version 16.3.6, 16.4.2, 16.5.1 or later to receive the security patch. After upgrading, verify that protected environment approval workflows are functioning correctly.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.37%
Probability of exploitation in next 30 days
31.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE