CVE-2023-6564

MEDIUM

GitLab EE Premium/Ultimate <16.4.3-16.6.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

References (1)

Core 1
Core References
Issue Tracking, Permissions Required issue-tracking permissions-required
https://gitlab.com/gitlab-com/gl-infra/production/-/issues/17213

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 7.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
gitlab/gitlab 16.4.3
gitlab/gitlab 16.5.3
gitlab/gitlab 16.6.1
Published Feb 08, 2024
Tracked Since Feb 18, 2026