HIGH

CVE-2023-5226

Gitlab GitLab 2023-12-01 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

Summary dbcve.org

GitLab contains a vulnerability where specially crafted branch names can bypass prohibited branch checks, allowing a malicious actor to manipulate repository content through the UI by circumventing branch protection mechanisms.

Mitigation

Upgrade GitLab to version 16.4.3, 16.5.3, or 16.6.1 or later to patch the vulnerability. Review existing branch protections and monitor for any suspicious branch names in existing repositories.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

0.55%
Probability of exploitation in next 30 days
44.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE