CVE-2023-5995: External user can abuse policy bot to gain access to internal projects
An issue has been discovered in GitLab EE affecting all versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the policy bot to gain access to internal projects.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-5995?
CVE-2023-5995 is a vulnerability in GitLab EE that allows an attacker to abuse the policy bot to gain access to internal projects.
What versions of GitLab EE are affected by CVE-2023-5995?
All versions starting from 16.2 before 16.4.3, all versions starting from 16.5 before 16.5.3, and version 16.6.0 are affected by CVE-2023-5995.
How severe is CVE-2023-5995?
CVE-2023-5995 has a severity rating of 7.5, making it a high-severity vulnerability.
How can an attacker exploit CVE-2023-5995?
An attacker can exploit CVE-2023-5995 by using the policy bot to gain unauthorized access to internal projects.
Where can I find more information about CVE-2023-5995?
More information about CVE-2023-5995 can be found at the following references: [GitLab issue](https://gitlab.com/gitlab-org/gitlab/-/issues/425361) and [HackerOne report](https://hackerone.com/reports/2138880).