An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.
2023-12-01T07:15:12.003
2024-11-21T08:41:19.753
Modified
CVSSv3.1: 4.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 16.4.3 | Yes |
Application | gitlab | gitlab | < 16.4.3 | Yes |
Application | gitlab | gitlab | < 16.5.3 | Yes |
Application | gitlab | gitlab | < 16.5.3 | Yes |
Application | gitlab | gitlab | 16.6.0 | Yes |
Application | gitlab | gitlab | 16.6.0 | Yes |