Vulnerability Description
An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 8.15, < 16.2.8 |
Related Weaknesses (CWE)
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/416957Broken Link
- https://hackerone.com/reports/2041789Permissions Required
- https://gitlab.com/gitlab-org/gitlab/-/issues/416957Broken Link
- https://hackerone.com/reports/2041789Permissions Required
FAQ
What is CVE-2023-5198?
CVE-2023-5198 is a vulnerability with a CVSS score of 4.3 (MEDIUM). An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a r...
How severe is CVE-2023-5198?
CVE-2023-5198 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5198?
Check the references section above for vendor advisories and patch information. Affected products include: Gitlab Gitlab.