4.3

CVE-2023-2022

Missing Authorization in GitLab

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version < 16.0.8
Gitlab ≫ GitLab SwEdition enterprise Version < 16.0.8
Gitlab ≫ GitLab SwEdition community Version >= 16.1 < 16.1.3
Gitlab ≫ GitLab SwEdition enterprise Version >= 16.1 < 16.1.3
Gitlab ≫ GitLab SwEdition community Version >= 16.2 < 16.2.2
Gitlab ≫ GitLab SwEdition enterprise Version >= 16.2 < 16.2.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.379
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
cve@gitlab.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-262 Not Using Password Aging

The product does not have a mechanism in place for managing password aging.

https://gitlab.com/gitlab-org/gitlab/-/issues/407166
Broken Link
https://hackerone.com/reports/1936572
Permissions Required