CVE-2023-4812: Bypass CODEOWNERS approval removal
An issue has been discovered in GitLab affecting all versions starting from 15.3 before 16.5.5, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request. This is a high severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N, 7.6). It is now mitigated in the latest release and is assigned CVE-2023-4812.
Other sources
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.
— NVD
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-4812?
CVE-2023-4812 is considered a critical vulnerability that allows the bypassing of CODEOWNERS approval in GitLab.
How do I fix CVE-2023-4812?
To fix CVE-2023-4812, upgrade GitLab to version 16.6.4 or later, or to version 16.7.2 or later.
Which GitLab versions are affected by CVE-2023-4812?
CVE-2023-4812 affects GitLab versions from 15.3 before 16.5.6, from 16.6 before 16.6.4, and from 16.7 before 16.7.2.
What impact does CVE-2023-4812 have on GitLab users?
CVE-2023-4812 can lead to unauthorized changes in a project without proper CODEOWNERS approval, jeopardizing project integrity.
Is CVE-2023-4812 applicable to both GitLab Community and Enterprise editions?
Yes, CVE-2023-4812 affects both GitLab Community and Enterprise editions across specified vulnerable versions.