MEDIUM
Missing Authorization in GitLab
Published Jan 12, 2024
6.6
MEDIUMCVSS 3.1
EPSS 0.55%
Description
A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.
Affected products
-
- Version 0StatusaffectedConstraints<16.5.6
- Version 16.6StatusaffectedConstraints<16.6.4
- Version 16.7StatusaffectedConstraints<16.7.2
- Version
OR
- < 16.5.6
- < 16.5.6
- ≥ 16.6.0 · < 16.6.4
- ≥ 16.6.0 · < 16.6.4
- 16.7.0
- 16.7.0
- 16.7.1
- 16.7.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 16.7.2, 16.6.4, 16.5.6 or above.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59151 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/432188 issue-trackingIssue TrackingVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-59151 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/432188 | issue-trackingIssue TrackingVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jan 12, 2024
Updated Jun 27, 2026
Reserved Dec 19, 2023
Link CVE-2023-6955
CISA Vulnrichment
Updated Jan 12, 2024
ENISA EUVD
EUVD-2023-59151 Assigner GitLab
Published Jan 12, 2024
Updated Jun 27, 2026
Exploited since n/a
Link EUVD-2023-59151