MEDIUM

CVE-2023-4812

Gitlab GitLab 2024-01-12 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.

Summary dbcve.org

A vulnerability in GitLab EE allows bypassing CODEOWNERS approval requirements by adding new changes to a previously approved merge request. The CODEOWNERS feature fails to re-evaluate approval requirements when additional commits are pushed to an already-approved MR, allowing unauthorized changes to proceed without required CODEOWNER review.

Mitigation

Upgrade GitLab EE to version 16.5.7, 16.6.5, 16.7.3, or later to patch this vulnerability.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.51%
Probability of exploitation in next 30 days
42.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE