MEDIUM

CVE-2023-6840

Gitlab GitLab 2024-02-07 CVSS v3.1
CVSS
6.7

Description

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

Summary dbcve.org

A maintainer-level user in GitLab EE can bypass security policies that block merge requests on protected branches by simply renaming the protected branch, effectively circumventing branch protection controls.

Mitigation

Update GitLab EE to versions 16.6.7, 16.7.5, 16.8.2 or later to patch this authorization bypass vulnerability.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.56%
Probability of exploitation in next 30 days
45.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE