5.3
CVSSv3

CVE-2023-6955

Published: 12/01/2024 Updated: 18/01/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An improper access control vulnerability exists in GitLab Remote Development affecting all versions before 16.5.6, 16.6 before 16.6.4 and 16.7 before 16.7.2. This condition allows an malicious user to create a workspace in one group that is associated with an agent from another group.

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab 16.7.0

gitlab gitlab 16.7.1

gitlab gitlab