PT-2023-8538 · Gitlab · Gitlab Ee Ultimate+2

Published

2023-12-06

·

Updated

2024-10-03

·

CVE-2023-6564

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE Premium and Ultimate versions 16.4.3 through 16.6.1
Description The issue is related to inadequate access control in GitLab, allowing subgroup members with the Developer role to potentially push or merge to protected branches in projects that use subgroups to define access permissions. This could enable a remote attacker to gain read and modify access to data.
Recommendations For versions 16.4.3, 16.5.3, and 16.6.1, consider restricting the Developer role in subgroups to prevent unauthorized access to protected branches until a fix is available. As a temporary workaround, review and adjust subgroup permissions to ensure that only intended members have push and merge access to protected branches. Restrict access to sensitive data and projects to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Improper Authorization

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-01132
BIT-GITLAB-2023-6564
CVE-2023-6564

Affected Products

Gitlab
Gitlab Ee Premium
Gitlab Ee Ultimate