VDB

CVE-2023-4658

CVE-2023-4658 PUBLISHED CVSS 3.0999999046325684 LOW

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

EPSS 0.47% · 38.0th percentile

Risk Scores

CVSS 3.1
3.0999999046325684
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.47%
38.0th percentile

Affected Products

VendorProductVersions
Bitnamigitlab8.13.0, 16.5.0, 16.6.0
Bitnamigitlab8.13.0, 16.5.0, 16.6.0

Timeline

  • Sep 28, 2023 CVE Published
  • Dec 1, 2023 EPSS Score
  • Dec 31, 2023 EPSS Score
  • Jan 30, 2024 EPSS Score
  • Feb 29, 2024 EPSS Score
  • Mar 30, 2024 EPSS Score
  • Apr 29, 2024 EPSS Score
  • May 29, 2024 EPSS Score
  • Jun 28, 2024 EPSS Score
  • Jul 29, 2024 EPSS Score
  • Aug 28, 2024 EPSS Score
  • Sep 27, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›