CVE-2023-3441: Exposure of Sensitive Information Due to Incompatible Policies in GitLab
An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3441?
CVE-2023-3441 is considered a moderate severity vulnerability as it relates to inadequate warning for merge rights on protected branches.
How do I fix CVE-2023-3441?
To fix CVE-2023-3441, upgrade your GitLab installation to version 16.4 or later.
Which versions of GitLab are affected by CVE-2023-3441?
CVE-2023-3441 affects all GitLab versions from 8.0 up to, but not including, version 16.4.
What are the security implications of CVE-2023-3441?
CVE-2023-3441 raises concerns over the potential for unauthorized code changes if merge rights are granted without proper warnings.
Is CVE-2023-3441 present in both GitLab EE and CE?
Yes, CVE-2023-3441 affects both GitLab Enterprise Edition (EE) and Community Edition (CE) across the specified versions.