Medium severity4.3NVD Advisory· Published Aug 2, 2023· Updated Jun 17, 2026
CVE-2023-2022
CVE-2023-2022
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 0
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <16.0.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <16.0.8
- Range: <16.0.8, 16.1<16.1.3, 16.2<16.2.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/407166nvdBroken Link
- hackerone.com/reports/1936572nvdPermissions Required
News mentions
1- GitLab Security Release: 16.2.2, 16.1.3, and 16.0.8GitLab Security Releases · Aug 1, 2023