CVE-2023-4700: Approval on protected environments can be bypassed
An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2023-4700.
What is the title of this vulnerability?
The title of this vulnerability is 'Improper Access Control in GitLab'.
What is the description of this vulnerability?
This vulnerability is an authorization issue in GitLab EE versions 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, which allows a user to run jobs in protected environments bypassing required approvals.
Which software versions are affected by this vulnerability?
This vulnerability affects GitLab EE versions 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1.
What is the severity of CVE-2023-4700?
The severity of CVE-2023-4700 is rated as medium with a CVSS score of 6.5.
What is the Common Weakness Enumeration (CWE) ID associated with this vulnerability?
The CWE ID associated with this vulnerability is CWE-284.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following references: [GitLab Issue](https://gitlab.com/gitlab-org/gitlab/-/issues/421937) and [HackerOne Report](https://hackerone.com/reports/2129826).