SB2023051130 - Security restrictions bypass in GitLab
Published: May 11, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security features bypass (CVE-ID: CVE-2023-2181)
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due in the refs/replace feature. A malicious developer can smuggle content into a merge request which would not be visible during review in the UI.
Remediation
Install update from vendor's website.