CVE-2023-6564

MEDIUM

GitLab EE Premium/Ultimate <16.4.3-16.6.1 - Privilege Escalation

Title source: llm

Description

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 6.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-863
Status published

Affected Products (3)

gitlab/gitlab
gitlab/gitlab
gitlab/gitlab

Timeline

Published Feb 08, 2024
Tracked Since Feb 18, 2026