MEDIUM
CVE-2023-6840
CVSS
6.7
Description
An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.
Summary dbcve.org
A maintainer-level user in GitLab EE can bypass security policies that block merge requests on protected branches by simply renaming the protected branch, effectively circumventing branch protection controls.
Mitigation
Update GitLab EE to versions 16.6.7, 16.7.5, 16.8.2 or later to patch this authorization bypass vulnerability.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.56%
Probability of exploitation in next 30 days
45.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.