HIGH
CVE-2023-5995
CVSS
7.5
Description
An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.
Summary dbcve.org
GitLab EE contains an access control bypass vulnerability in the policy bot component. Attackers can exploit the policy bot to gain unauthorized access to internal projects that should be restricted, bypassing intended authorization boundaries.
Mitigation
Upgrade GitLab EE to version 16.4.3, 16.5.3, 16.6.1 or later. If immediate upgrade is not possible, restrict or disable the policy bot feature for internal projects as a temporary workaround.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.56%
Probability of exploitation in next 30 days
45.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.