MEDIUM
CVE-2023-4812
CVSS
5.3
Description
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.
Summary dbcve.org
A vulnerability in GitLab EE allows bypassing CODEOWNERS approval requirements by adding new changes to a previously approved merge request. The CODEOWNERS feature fails to re-evaluate approval requirements when additional commits are pushed to an already-approved MR, allowing unauthorized changes to proceed without required CODEOWNER review.
Mitigation
Upgrade GitLab EE to version 16.5.7, 16.6.5, 16.7.3, or later to patch this vulnerability.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.51%
Probability of exploitation in next 30 days
42.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.