PT-2024-1686 · Gitlab · Gitlab Ce/Ee+1

Js_Noob

·

Published

2024-02-07

·

Updated

2024-10-03

·

CVE-2023-6840

CVSS v2.0

8.0

High

VectorAV:N/AC:L/Au:M/C:P/I:C/A:C
Name of the Vulnerable Software and Affected Versions GitLab EE versions 16.4 through 16.6.7 GitLab EE versions 16.7 through 16.7.5 GitLab EE versions 16.8 through 16.8.2
Description The issue allows a maintainer to change the name of a protected branch, bypassing the security policy added to block merge requests. This is related to insufficient access control in the GitLab platform. An attacker could exploit this to remotely bypass existing security restrictions.
Recommendations For GitLab EE versions 16.4 through 16.6.7, update to version 16.6.7 or later. For GitLab EE versions 16.7 through 16.7.5, update to version 16.7.5 or later. For GitLab EE versions 16.8 through 16.8.2, update to version 16.8.2 or later.

Exploit

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-01374
BIT-GITLAB-2023-6840
CVE-2023-6840

Affected Products

Gitlab
Gitlab Ce/Ee