MEDIUM
Incorrect Authorization in GitLab
Published Sep 29, 2023
4.3
MEDIUMCVSS 3.1
EPSS 0.47%
Description
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.
Affected products
-
- Version 10.6StatusaffectedConstraints<16.2.8
- Version 16.3StatusaffectedConstraints<16.3.5
- Version 16.4StatusaffectedConstraints<16.4.1
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 16.4.1, 16.3.5, 16.2.8
Weaknesses (1)
References (2)
- https://gitlab.com/gitlab-org/gitlab/-/issues/419972 issue-trackingpermissions-requiredBroken Link
- https://hackerone.com/reports/2082560 technical-descriptionexploitpermissions-requiredbroken-linkPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/419972 | issue-trackingpermissions-requiredBroken Link | |
| https://hackerone.com/reports/2082560 | technical-descriptionexploitpermissions-requiredbroken-linkPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Sep 29, 2023
Updated Aug 14, 2026
Reserved Jul 27, 2023
Link CVE-2023-3979
CISA Vulnrichment
Updated Jul 25, 2024