CVE-2023-3979 is a medium-severity vulnerability affecting GitLab versions prior to 16.2.8, 16.3.5, and 16.4.1, where upstream members could gain unintended write permissions to a merge request's source branch. With a CVSS score of 4.3, this low-complexity vulnerability allows an authenticated attacker to impact data integrity (I:L) without user interaction. There is no evidence of active exploitation, nor are there public exploit modules available in Metasploit, Nuclei, or ExploitDB. Despite minimal community discussion and media coverage, GitLab has released security updates to address this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.6, < 16.2.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 10.6, < 16.2.8CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 16.3.0, < 16.3.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 16.3.0, < 16.3.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
16.4.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.