CVE-2023-4700

Source
https://cve.org/CVERecord?id=CVE-2023-4700
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4700.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-4700
Aliases
Published
2023-11-06T17:30:35.198Z
Modified
2026-04-10T05:04:02.257184Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N CVSS Calculator
Summary
Missing Authorization in GitLab
Details

An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.

Database specific
{
    "cna_assigner": "GitLab",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/4xxx/CVE-2023-4700.json"
}
References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "14.7"
        },
        {
            "fixed": "16.3.6"
        }
    ]
}
Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "16.4.0"
        },
        {
            "fixed": "16.4.2"
        }
    ]
}
Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
{
    "versions": [
        {
            "introduced": "16.5.0"
        },
        {
            "fixed": "16.5.1"
        }
    ]
}

Affected versions

v16.*
v16.4.0-ee
v16.5.0-ee

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-4700.json"