Description
An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to versions 16.4.3, 16.5.3, 16.6.1 or above.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-57555 | An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI. |
References
History
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2025-11-20T04:10:33.281Z
Reserved: 2023-09-27T13:01:23.089Z
Link: CVE-2023-5226
No data.
Status : Modified
Published: 2023-12-01T07:15:12.003
Modified: 2024-11-21T08:41:19.753
Link: CVE-2023-5226
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD