Loading HuntDB...

GHSA-5p8h-m559-wpw7

GitHub Security Advisory

⚠ Unreviewed LOW Has CVE

Advisory Details

An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest user, when granted the permission through a group.

Related CVEs

Key Information

GHSA ID
GHSA-5p8h-m559-wpw7
Published
December 1, 2023 9:30 AM
Last Modified
December 1, 2023 9:30 AM
CVSS Score
2.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 16, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.