MEDIUM

CVE-2023-6564

Gitlab GitLab 2024-02-08 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

Summary dbcve.org

GitLab EE Premium and Ultimate versions 16.4.3, 16.5.3, and 16.6.1 contain an access control bypass where subgroup members with the Developer role could push or merge to protected branches even when they should not have been permitted, due to improper enforcement of subgroup-based protected branch permissions.

Mitigation

Upgrade GitLab to a patched version. Additionally, audit protected branch settings and subgroup memberships to ensure only intended users have push/merge permissions.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.38%
Probability of exploitation in next 30 days
31.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE