CVE-2023-3979: Incorrect Authorization in GitLab
An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get permission to write to the merge request’s source branch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.4.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.3.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.2.8
Event History
Frequently Asked Questions
What is CVE-2023-3979?
CVE-2023-3979 is an issue discovered in GitLab affecting multiple versions before 16.2.8 and 16.3.5.
What is the severity of CVE-2023-3979?
The severity of CVE-2023-3979 is medium with a CVSS score of 4.3.
Which versions of GitLab are affected by CVE-2023-3979?
All versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, and version 16.4.0.
How can I fix CVE-2023-3979?
Upgrade to GitLab version 16.2.8, 16.3.5, or 16.4.1 to fix CVE-2023-3979.
Where can I find more information about CVE-2023-3979?
More information about CVE-2023-3979 can be found at the following references: - [GitLab Issue](https://gitlab.com/gitlab-org/gitlab/-/issues/419972) - [HackerOne Report](https://hackerone.com/reports/2082560)