CVE-2023-6564

Source
https://cve.org/CVERecord?id=CVE-2023-6564
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6564.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-6564
Aliases
Downstream
Published
2024-02-08T11:30:52Z
Modified
2026-08-27T11:30:21Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Incorrect Authorization in GitLab
Details

An issue has been discovered in GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1. In projects using subgroups to define who can push and/or merge to protected branches, there may have been instances in which subgroup members with the Developer role were able to push or merge to protected branches.

Database specific
{
    "cna_assigner": "GitLab",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/6xxx/CVE-2023-6564.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "16.4.3"
                },
                {
                    "fixed": "16.4.4"
                },
                {
                    "introduced": "16.5.3"
                },
                {
                    "fixed": "16.5.4"
                },
                {
                    "introduced": "16.6.1"
                },
                {
                    "fixed": "16.6.2"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / gitlab.com/gitlab-org/gitlab

Affected ranges

Type
GIT
Repo
https://gitlab.com/gitlab-org/gitlab
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:gitlab:gitlab:16.4.3:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:gitlab:gitlab:16.5.3:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:gitlab:gitlab:16.6.1:*:*:*:enterprise:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "16.4.3"
        },
        {
            "last_affected": "16.4.3"
        },
        {
            "introduced": "16.5.3"
        },
        {
            "last_affected": "16.5.3"
        },
        {
            "introduced": "16.6.1"
        },
        {
            "last_affected": "16.6.1"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

16.*
16.4.3
16.5.3
16.6.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-6564.json"