HIGH

CVE-2023-5995

Gitlab GitLab 2023-12-01 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.

Summary dbcve.org

GitLab EE contains an access control bypass vulnerability in the policy bot component. Attackers can exploit the policy bot to gain unauthorized access to internal projects that should be restricted, bypassing intended authorization boundaries.

Mitigation

Upgrade GitLab EE to version 16.4.3, 16.5.3, 16.6.1 or later. If immediate upgrade is not possible, restrict or disable the policy bot feature for internal projects as a temporary workaround.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.56%
Probability of exploitation in next 30 days
45.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE