CVE Vulnerabilities

CVE-2023-5226

Published: Dec 01, 2023 | Modified: Dec 06, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab * 16.4.3 (excluding)
Gitlab Gitlab 16.5.0 (including) 16.5.3 (excluding)
Gitlab Gitlab 16.6.0 (including) 16.6.0 (including)
Gitlab Ubuntu bionic *
Gitlab Ubuntu esm-apps/xenial *
Gitlab Ubuntu trusty *
Gitlab Ubuntu xenial *

References