CVE-2023-4379: Incorrect Authorization in GitLab
Published Nov 9, 2023
·Updated
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.
Affected Software
3 affected components
GitLab GitLab>=15.3.0<16.2.8
GitLab GitLab>=16.3.0<16.3.5
GitLab GitLab=16.4.0
Remediation
Information
Upgrade to version 16.2.8, 16.3.5, 16.4.1 or above
Event History
Nov 9, 2023
CVE Published
via MITRE·09:01 PM
Data Sourced
via MITRE·09:01 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-4379?
CVE-2023-4379 is a vulnerability in GitLab EE that allows improper access control.
2
Which versions of GitLab EE are affected by CVE-2023-4379?
All versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 are affected by CVE-2023-4379.
3
What is the severity of CVE-2023-4379?
CVE-2023-4379 has a severity rating of 8.1 (High).
4
How does CVE-2023-4379 work?
CVE-2023-4379 allows code owner approval to remain on merge requests even when the target branch is updated in GitLab EE.
5
Is there a fix available for CVE-2023-4379?
Yes, the fix is available in GitLab versions 16.2.8, 16.3.5, and 16.4.1.