CVE-2023-6955
Description
A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.
Summary dbcve.org
A missing authorization check in GitLab Remote Development allows users to create workspaces in one group while associating them with an agent from a different group. This cross-group agent association bypasses proper permission boundaries, enabling unauthorized access to resources controlled by agents in groups the user should not have access to.
Mitigation
Upgrade GitLab to version 16.5.6, 16.6.4, 16.7.2 or later to obtain the patch that adds proper authorization validation for workspace-agent group associations.