CVE-2023-3441

MEDIUM

GitLab EE/CE <16.4 - Info Disclosure

Title source: llm

Description

An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not sufficiently warn about security implications of granting merge rights to protected branches.

Scores

CVSS v3 6.6
EPSS 0.0011
EPSS Percentile 29.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N

Classification

CWE
CWE-213
Status published

Affected Products (2)

gitlab/gitlab < 16.4.0
gitlab/gitlab < 16.4.0

Timeline

Published Oct 01, 2024
Tracked Since Feb 18, 2026