PT-2024-1686 · Gitlab · Gitlab Ce/Ee+1
Js_Noob
·
Published
2024-02-07
·
Updated
2024-10-03
·
CVE-2023-6840
CVSS v2.0
8.0
High
| Vector | AV:N/AC:L/Au:M/C:P/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GitLab EE versions 16.4 through 16.6.7
GitLab EE versions 16.7 through 16.7.5
GitLab EE versions 16.8 through 16.8.2
Description
The issue allows a maintainer to change the name of a protected branch, bypassing the security policy added to block merge requests. This is related to insufficient access control in the GitLab platform. An attacker could exploit this to remotely bypass existing security restrictions.
Recommendations
For GitLab EE versions 16.4 through 16.6.7, update to version 16.6.7 or later.
For GitLab EE versions 16.7 through 16.7.5, update to version 16.7.5 or later.
For GitLab EE versions 16.8 through 16.8.2, update to version 16.8.2 or later.
Exploit
Fix
Improper Access Control
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee