CVE-2023-3441

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Oct 1, 2024
Updated: Dec 12, 2024
CWE ID 787

Summary

CVE-2023-3441 is a vulnerability affecting GitLab Enterprise Edition (EE) and Community Edition (CE) starting from version 8.0. The issue lies in the insufficient warning given when merge rights are granted to protected branches. This lack of clear communication about the security implications of such actions may lead to unintended access or modifications to protected branches. Organizations using GitLab EE or CE versions prior to 16.4 are urged to update to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share