CVE-2023-4379
Last modified
CVE-2023-4379 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.. EPSS estimates a 0.50% chance of exploitation in the next 30 days.
Description
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1. Code owner approval was not removed from merge requests when the target branch was updated.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 15.3.0, < 16.2.8 |
| Gitlab | Gitlab | >= 16.3.0, < 16.3.5 |
| Gitlab | Gitlab | 16.4.0 |
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/415496Issue Tracking
- https://gitlab.com/gitlab-org/gitlab/-/issues/415496Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-4379?
How severe is CVE-2023-4379?
How do I fix CVE-2023-4379?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-43784Plesk Onyx 17.8.11 has accessKeyId and secretAccessKey field…7.5
- CVE-2023-43785A vulnerability was found in libX11 due to a boundary condit…5.5
- CVE-2023-43786A vulnerability was found in libX11 due to an infinite loop …5.5
- CVE-2023-43787A vulnerability was found in libX11 due to an integer overfl…7.8
- CVE-2023-43788A vulnerability was found in libXpm due to a boundary condit…5.5
- CVE-2023-43789A vulnerability was found in libXpm where a vulnerability ex…5.5
- CVE-2023-43790iTop is an IT service management platform. By manipulating …5.4
- CVE-2023-43791Label Studio is a multi-type data labeling and annotation to…8.8
- CVE-2023-43792baserCMS is a website development framework. In versions 4.6…9.8
- CVE-2023-43793Misskey is an open source, decentralized social media platfo…7.5
- CVE-2023-43794Nocodb is an open source Airtable alternative. Affected vers…4.9
- CVE-2023-43795GeoServer is an open source software server written in Java …9.8
Are you affected by CVE-2023-4379?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
