CVE-2023-6564
Description
An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.
Summary dbcve.org
GitLab EE Premium and Ultimate versions 16.4.3, 16.5.3, and 16.6.1 contain an access control bypass where subgroup members with the Developer role could push or merge to protected branches even when they should not have been permitted, due to improper enforcement of subgroup-based protected branch permissions.
Mitigation
Upgrade GitLab to a patched version. Additionally, audit protected branch settings and subgroup memberships to ensure only intended users have push/merge permissions.