PT-2023-8538 · Gitlab · Gitlab Ee Ultimate+2

CVE-2023-6564

·

Publicado

2023-12-06

·

Atualizado

2024-10-03

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE Premium and Ultimate versions 16.4.3 through 16.6.1
Description The issue is related to inadequate access control in GitLab, allowing subgroup members with the Developer role to potentially push or merge to protected branches in projects that use subgroups to define access permissions. This could enable a remote attacker to gain read and modify access to data.
Recommendations For versions 16.4.3, 16.5.3, and 16.6.1, consider restricting the Developer role in subgroups to prevent unauthorized access to protected branches until a fix is available. As a temporary workaround, review and adjust subgroup permissions to ensure that only intended members have push and merge access to protected branches. Restrict access to sensitive data and projects to minimize the risk of exploitation.

Exploit

Correção

Improper Privilege Management

Improper Authorization

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-01132
BIT-GITLAB-2023-6564
CVE-2023-6564

Produtos afetados

Gitlab
Gitlab Ee Premium
Gitlab Ee Ultimate