CVE-2023-6955 — Missing Authorization in Gitlab
Severity
5.3MEDIUMNVD
EPSS
0.0%
top 90.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 12
Description
A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2. This condition allows an attacker to create a workspace in one group that is associated with an agent from another group.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages4 packages
🔴Vulnerability Details
2📋Vendor Advisories
2GitLab▶
CVE-2023-6955: A missing authorization check vulnerability exists in GitLab Remote Development affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7↗2024-01-12
Debian▶
CVE-2023-6955: gitlab - A missing authorization check vulnerability exists in GitLab Remote Development ...↗2023