2024-01-12 15:00:29 +00:00
{
"id" : "CVE-2023-4812" ,
"sourceIdentifier" : "cve@gitlab.com" ,
"published" : "2024-01-12T14:15:48.510" ,
2024-01-18 23:00:28 +00:00
"lastModified" : "2024-01-18T21:18:27.850" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-01-12 15:00:29 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2. The required CODEOWNERS approval could be bypassed by adding changes to a previously approved merge request."
2024-01-18 23:00:28 +00:00
} ,
{
"lang" : "es" ,
"value" : "Se descubri\u00f3 un problema en GitLab EE que afecta a todas las versiones desde 15.3 anteriores a 16.5.6, todas las versiones desde 16.6 anteriores a 16.6.4, todas las versiones desde 16.7 anteriores a 16.7.2. La aprobaci\u00f3n requerida de CODEOWNERS podr\u00eda omitirse agregando cambios a una solicitud de fusi\u00f3n previamente aprobada."
2024-01-12 15:00:29 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-01-18 23:00:28 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.3 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 1.4
} ,
2024-01-12 15:00:29 +00:00
{
"source" : "cve@gitlab.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "HIGH" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 7.6 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 2.3 ,
"impactScore" : 4.7
}
]
} ,
"weaknesses" : [
2024-01-18 23:00:28 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
} ,
2024-01-12 15:00:29 +00:00
{
"source" : "cve@gitlab.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-284"
}
]
}
] ,
2024-01-18 23:00:28 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*" ,
"versionStartIncluding" : "15.3.0" ,
"versionEndExcluding" : "16.5.5" ,
"matchCriteriaId" : "B4DEAEEE-6DB8-4426-B577-97961307110D"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*" ,
"versionStartIncluding" : "15.3.0" ,
"versionEndExcluding" : "16.5.5" ,
"matchCriteriaId" : "D547FEBC-A6BC-4057-B23D-1A7F91DFAF47"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*" ,
"versionStartIncluding" : "16.6.0" ,
"versionEndExcluding" : "16.6.4" ,
"matchCriteriaId" : "7198B7E4-9928-4B7D-9D00-6B76CCAC3875"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*" ,
"versionStartIncluding" : "16.6.0" ,
"versionEndExcluding" : "16.6.4" ,
"matchCriteriaId" : "D294EA47-B2EF-42D6-A92B-93CEA5D209B7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:enterprise:*:*:*" ,
"matchCriteriaId" : "29C6355F-1CD3-4E4A-AACA-19B497A631D6"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:enterprise:*:*:*" ,
"matchCriteriaId" : "77D86BC4-D4DD-4848-B0FD-0C16A3D2DF89"
}
]
}
]
}
] ,
2024-01-12 15:00:29 +00:00
"references" : [
{
"url" : "https://gitlab.com/gitlab-org/gitlab/-/issues/424398" ,
2024-01-18 23:00:28 +00:00
"source" : "cve@gitlab.com" ,
"tags" : [
"Broken Link"
]
2024-01-12 15:00:29 +00:00
} ,
{
"url" : "https://hackerone.com/reports/2115574" ,
2024-01-18 23:00:28 +00:00
"source" : "cve@gitlab.com" ,
"tags" : [
"Permissions Required"
]
2024-01-12 15:00:29 +00:00
}
]
}