CVE Vulnerabilities

CVE-2023-4658

Published: Dec 01, 2023 | Modified: Dec 06, 2023
CVSS 3.x
3.1
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the Allowed to merge permission as a guest user, when granted the permission through a group.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 8.13.0 (including) 16.4.3 (excluding)
Gitlab Gitlab 16.5.0 (including) 16.5.3 (excluding)
Gitlab Gitlab 16.6.0 (including) 16.6.0 (including)

References