CVE-2023-6564
MEDIUMGitLab EE Premium/Ultimate <16.4.3-16.6.1 - Privilege Escalation
Title source: llmDescription
An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.
Scores
CVSS v3
6.5
EPSS
0.0003
EPSS Percentile
6.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-863
Status
published
Affected Products (3)
gitlab/gitlab
gitlab/gitlab
gitlab/gitlab
Timeline
Published
Feb 08, 2024
Tracked Since
Feb 18, 2026