VulnerabilityModified
CVE-2023-4812
The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.
MEDIUM 5.3EPSS 0.51%
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/424398Broken Link
- https://hackerone.com/reports/2115574Permissions Required
- https://gitlab.com/gitlab-org/gitlab/-/issues/424398Broken Link
- https://hackerone.com/reports/2115574Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.