Severity
6.7MEDIUMNVD
EPSS
0.0%
top 99.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 7
Latest updateFeb 13

Description

An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:HExploitability: 1.2 | Impact: 5.5

Affected Packages5 packages

CVEListV5gitlab/gitlab16.416.6.7+2
NVDgitlab/gitlab16.4.016.6.7+2
debiandebian/gitlab< gitlab 16.6.7-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-8jj6-7vgp-rg47: An issue has been discovered in GitLab EE affecting all versions from 162024-02-08
OSV
CVE-2023-6840: An issue has been discovered in GitLab EE affecting all versions from 162024-02-07

📋Vendor Advisories

3
Red Hat
bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator2024-02-13
GitLab
CVE-2023-6840: An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allow2024-02-07
Debian
CVE-2023-6840: gitlab - An issue has been discovered in GitLab EE affecting all versions from 16.4 prior...2023