← back
CVE-2023-6840mediumCWE-862

Missing Authorization in GitLab

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.7epss 0.6%
exploitation probability
0.6%top 56% of all CVEs
observed exploitation
nono source reports it
An issue has been discovered in GitLab EE affecting all versions from 16.4 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 which allows a maintainer to change the name of a protected branch that bypasses the security policy added to block MR.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
Affected products
GitLab · GitLab