An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gitlab | Gitlab | * | 16.4.3 (excluding) |
Gitlab | Gitlab | 16.5.0 (including) | 16.5.3 (excluding) |
Gitlab | Gitlab | 16.6.0 (including) | 16.6.0 (including) |
Gitlab | Ubuntu | bionic | * |
Gitlab | Ubuntu | esm-apps/xenial | * |
Gitlab | Ubuntu | trusty | * |
Gitlab | Ubuntu | xenial | * |