GitLab released security updates for Community Edition and Enterprise Edition in versions 16.6.1, 16.5.3, and 16.4.3, urging affected self-managed installations to upgrade immediately. The fixes addressed multiple vulnerabilities spanning XSS, privilege escalation, information disclosure, authorization bypass, package registry access issues, protected branch and pipeline schedule permission bypasses, and client-side denial of service. The most severe issue was CVE-2023-6033, a high-severity cross-site scripting flaw in Jira integration configuration, while GitLab said GitLab.com was already running the patched version.
One of the patched Enterprise Edition issues, CVE-2023-4658, was an incorrect authorization flaw that allowed a guest user to abuse the "Allowed to merge" permission when that right was inherited through a group. GitLab rated that bug CVSS 3.1 / Low and said it affected versions from 8.13 before 16.4.3, 16.5 before 16.5.3, and 16.6 before 16.6.1. The release also included fixes for unauthorized access to release descriptions and other EE-specific authorization weaknesses, along with bundled component updates for Mattermost, PostgreSQL, and pcre2.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record states that CVE-2023-4658, an incorrect authorization flaw in GitLab EE involving the "Allowed to merge" permission granted through a group, was published on 2023-12-01. The record attributes the report to theluci through GitLab's HackerOne bug bounty program.
On 2023-11-30, GitLab released security updates for Community Edition and Enterprise Edition in versions 16.6.1, 16.5.3, and 16.4.3, fixing multiple vulnerabilities including CVE-2023-6033 and several authorization and privilege issues. GitLab urged affected installations to upgrade immediately and said GitLab.com was already running the patched version.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.