CVE-2023-5226
Description
An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.
Summary dbcve.org
GitLab contains a vulnerability where specially crafted branch names can bypass prohibited branch checks, allowing a malicious actor to manipulate repository content through the UI by circumventing branch protection mechanisms.
Mitigation
Upgrade GitLab to version 16.4.3, 16.5.3, or 16.6.1 or later to patch the vulnerability. Review existing branch protections and monitor for any suspicious branch names in existing repositories.