VDB

CVE-2023-3444

CVE-2023-3444 PUBLISHED CVSS 6.5 MEDIUM

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

EPSS 0.52% · 42.0th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS Score
0.52%
42.0th percentile

Affected Products

VendorProductVersions
Bitnamigitlab15.3.0, 16.0.0, 16.1.0
Bitnamigitlab15.3.0, 16.0.0, 16.1.0

Timeline

  • Jun 29, 2023 CVE Published
  • Jul 14, 2023 EPSS Score
  • Aug 18, 2023 EPSS Score
  • Sep 22, 2023 EPSS Score
  • Oct 27, 2023 EPSS Score
  • Dec 1, 2023 EPSS Score
  • Jan 5, 2024 EPSS Score
  • Feb 9, 2024 EPSS Score
  • Mar 15, 2024 EPSS Score
  • Apr 19, 2024 EPSS Score
  • May 24, 2024 EPSS Score
  • Jun 28, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›