Severity
5.3MEDIUMNVD
EPSS
0.0%
top 90.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 12

Description

A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

CVEListV5gitlab/gitlab16.616.6.4+1
NVDgitlab/gitlab16.6.016.6.4+3
debiandebian/gitlab< gitlab 16.6.5-3 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2023-6955: A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 162024-01-12
GHSA
GHSA-2w7q-mj4w-9cm2: An improper access control vulnerability exists in GitLab Remote Development affecting all versions prior to 162024-01-12

📋Vendor Advisories

2
GitLab
CVE-2023-6955: A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.72024-01-12
Debian
CVE-2023-6955: gitlab - A missing authorization check vulnerability exists in GitLab Remote Development ...2023

🕵️Threat Intelligence

1
Bleepingcomputer
GitLab warns of critical zero-click account hijacking vulnerability2024-01-12