VYPR
Medium severity4.3NVD Advisory· Published Aug 2, 2023· Updated Jun 17, 2026

CVE-2023-2022

CVE-2023-2022

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2, which leads to developers being able to create pipeline schedules on protected branches even if they don't have access to merge

Affected products

5
  • GitLab Inc./GitLabv53 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 0
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <16.0.8
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <16.0.8
  • Range: <16.0.8, 16.1<16.1.3, 16.2<16.2.2
  • osv-coords
    Range: < 16.0.8

Patches

Vulnerability mechanics

References

2

News mentions

1