An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.
History

Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2023-12-01T07:01:43.131Z

Updated: 2024-09-18T04:07:50.190Z

Reserved: 2023-09-27T13:01:23.089Z

Link: CVE-2023-5226

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-01T07:15:12.003

Modified: 2024-11-21T08:41:19.753

Link: CVE-2023-5226

cve-icon Redhat

No data.