Low severity2.0NVD Advisory· Published Dec 15, 2023· Updated Jun 17, 2026
CVE-2023-3511
CVE-2023-3511
Description
An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private projects they're not a member of.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 8.17
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.17,<16.4.4
- (no CPE)range: starting from 8.17 before 16.4.4, starting from 16.5 before 16.5.4, starting from 16.6 before 16.6.2
- Range: starting from 8.17 before 16.4.4, starting from 16.5 before 16.5.4, starting from 16.6 before 16.6.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/416961nvdBroken Link
- hackerone.com/reports/2046752nvdPermissions Required
News mentions
1- GitLab Security Release: 16.6.2, 16.5.4, 16.4.4GitLab Security Releases · Dec 13, 2023