QID 379246
QID 379246: GitLab EE/CE Bypass Required Approvals Vulnerability (CVE-2023-4812)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-4812: An issue has been discovered in GitLab EE/CE where the required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request.
Affected Versions:
GitLab CE/EE v15.3 before 16.5.5, v16.6 before 16.6.4, v16.7 before 16.7.2
QID Detection Logic:(Authenticated)(Linux)
The QID fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability can lead to merging of malicious code without code owners approval.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Releases
Vendor References
CVEs related to QID 379246
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-4812 |
|