Back

MEDIUM

Missing Authorization in GitLab

Published Jan 12, 2024

Description

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

Affected products

Remediation

Vendor solution

Upgrade to versions 16.7.2, 16.6.4, 16.5.6 or above.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Jan 12, 2024
Updated Jun 27, 2026
Reserved Dec 19, 2023
CISA Vulnrichment
Updated Jan 12, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitLab
Published Jan 12, 2024
Updated Jun 27, 2026
Exploited since n/a
EUVD-2023-59151