CVE-2023-2576: Incorrect Authorization in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. This allowed a developer to remove the CODEOWNERS rules and merge to a protected branch.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2023-2576.
What is the severity level of CVE-2023-2576?
The severity level of CVE-2023-2576 is medium (4.3).
Which versions of GitLab CE/EE are affected by CVE-2023-2576?
All versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, and all versions starting from 16.1 before 16.1.1 of GitLab CE/EE are affected.
What is the impact of CVE-2023-2576?
The vulnerability allows a developer to remove the CODEOWNERS rules and merge to a protected branch in GitLab CE/EE.
Are there any references for CVE-2023-2576?
Yes, there are references available at: [GitLab Issue](https://gitlab.com/gitlab-org/gitlab/-/issues/410123) and [HackerOne Report](https://hackerone.com/reports/1898054).