Low severity3.1NVD Advisory· Published Dec 1, 2023· Updated Jun 17, 2026
CVE-2023-4658
CVE-2023-4658
Description
An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the Allowed to merge permission as a guest user, when granted the permission through a group.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 8.13
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.13.0,<16.4.3
- cpe:2.3:a:gitlab:gitlab:16.6.0:*:*:*:enterprise:*:*:*
- (no CPE)range: <16.4.3, <16.5.3, <16.6.1
- Range: <16.4.3, <16.5.3, <16.6.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/423835nvdBroken LinkVendor Advisory
- hackerone.com/reports/2104540nvdPermissions RequiredThird Party Advisory
News mentions
2- GitLab Security Release: 16.6.1, 16.5.3, 16.4.3GitLab Security Releases · Nov 30, 2023
- GitLab Security Release: 16.4.1, 16.3.5, and 16.2.8GitLab Security Releases · Sep 28, 2023