First published: Fri Dec 01 2023(Updated: )
An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab GitLab | >=16.2.0<16.4.3 | |
GitLab GitLab | >=16.5.0<16.5.3 | |
GitLab GitLab | =16.6.0 |
Upgrade to version 16.4.3, 16.5.3, 16.6.1, or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5995 is a vulnerability in GitLab EE that allows an attacker to abuse the policy bot to gain access to internal projects.
All versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, and version 16.6.0 are affected by CVE-2023-5995.
CVE-2023-5995 has a severity rating of 7.5, making it a high-severity vulnerability.
An attacker can exploit CVE-2023-5995 by using the policy bot to gain unauthorized access to internal projects.
More information about CVE-2023-5995 can be found at the following references: [GitLab issue](https://gitlab.com/gitlab-org/gitlab/-/issues/425361) and [HackerOne report](https://hackerone.com/reports/2138880).