PT-2023-24628 · Gitlab · Gitlab

Byst4Nly0N

·

Published

2023-08-02

·

Updated

2024-03-06

·

CVE-2023-3401

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions prior to 16.0.8 GitLab versions 16.1 prior to 16.1.3 GitLab versions 16.2 prior to 16.2.2
Description An issue has been discovered in GitLab where the main branch of a repository with a specially designed name allows an attacker to create repositories with malicious code.
Recommendations For versions prior to 16.0.8, update to version 16.0.8 or later. For versions 16.1 prior to 16.1.3, update to version 16.1.3 or later. For versions 16.2 prior to 16.2.2, update to version 16.2.2 or later.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2023-3401
CVE-2023-3401

Affected Products

Gitlab