LOW
Incorrect Authorization in GitLab
Published Dec 1, 2023
3.1
LOWCVSS 3.1
EPSS 0.47%
Description
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.
Affected products
-
- Version 16.5StatusaffectedConstraints<16.5.3
- Version 16.6StatusaffectedConstraints<16.6.1
- Version 8.13StatusaffectedConstraints<16.4.3
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 16.4.3, 16.5.3, 16.6.1 or above.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54510 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/423835 issue-trackingpermissions-requiredBroken LinkVendor Advisory
- https://hackerone.com/reports/2104540 technical-descriptionexploitpermissions-requiredPermissions RequiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-54510 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/423835 | issue-trackingpermissions-requiredBroken LinkVendor Advisory | |
| https://hackerone.com/reports/2104540 | technical-descriptionexploitpermissions-requiredPermissions RequiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Dec 1, 2023
Updated Apr 26, 2026
Reserved Aug 31, 2023
Link CVE-2023-4658
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2023-54510 Assigner GitLab
Published Dec 1, 2023
Updated Apr 26, 2026
Exploited since n/a
Link EUVD-2023-54510