MEDIUM
Incorrect Authorization in GitLab
Published Jul 13, 2023
4.3
MEDIUMCVSS 3.1
EPSS 0.47%
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch.
Affected products
-
Affected
- ≥ 13.7, < 15.11.10
- ≥ 16.0, < 16.0.6
- ≥ 16.1, < 16.1.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 15.11.10, 16.0.6, 16.1.1 or above.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34054 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/410123 issue-trackingBroken LinkVendor Advisory
- https://hackerone.com/reports/1898054 technical-descriptionexploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34054 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/410123 | issue-trackingBroken LinkVendor Advisory | |
| https://hackerone.com/reports/1898054 | technical-descriptionexploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jul 13, 2023
Updated Oct 30, 2024
Reserved May 8, 2023
Link CVE-2023-2576
CISA Vulnrichment
Updated Oct 30, 2024
Red Hat
No data
GitHub
No data