CVE-2023-5198

Source
https://cve.org/CVERecord?id=CVE-2023-5198
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5198.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-5198
Aliases
Downstream
Published
2023-09-29T07:01:42.219Z
Modified
2026-08-27T11:47:27.184381502Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Incorrect Authorization in GitLab
Details

An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5198.json",
    "cwe_ids": [
        "CWE-863"
    ],
    "cna_assigner": "GitLab"
}
References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
Show details
{
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "cpe": [
        "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
        "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*",
        "cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "8.15"
        },
        {
            "fixed": "16.2.8"
        },
        {
            "introduced": "16.3.0"
        },
        {
            "fixed": "16.3.5"
        },
        {
            "introduced": "16.4.0"
        },
        {
            "last_affected": "16.4.0"
        }
    ]
}

Affected versions

16.*
16.4.0
v16.*
v16.3.0-ee
v16.3.2-ee
v16.3.3-ee
v16.4.0-ee

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5198.json"