PT-2023-27107 · Gitlab · Gitlab

Thelucion

·

Published

2023-09-28

·

Updated

2024-10-03

·

CVE-2023-3979

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 10.6 through 16.2.8 GitLab versions 16.3 through 16.3.5 GitLab versions 16.4 through 16.4.1
Description An issue has been discovered in GitLab where upstream members collaborating on a branch could get permission to write to the merge request's source branch.
Recommendations For GitLab versions 10.6 through 16.2.8, update to version 16.2.8 or later. For GitLab versions 16.3 through 16.3.5, update to version 16.3.5 or later. For GitLab versions 16.4 through 16.4.1, update to version 16.4.1 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2023-3979
CVE-2023-3979

Affected Products

Gitlab