VYPR
Low severity3.5NVD Advisory· Published Nov 6, 2023· Updated Jun 17, 2026

CVE-2023-4700

CVE-2023-4700

Description

An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.

Affected products

5
  • GitLab Inc./GitLabv53 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 14.7
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=14.7.0,<16.3.6
    • cpe:2.3:a:gitlab:gitlab:16.5.0:*:*:*:enterprise:*:*:*
  • Range: from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1
  • osv-coords
    Range: >= 14.7.0, < 16.3.6

Patches

Vulnerability mechanics

References

2

News mentions

1