{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-17T05:24:54.526","vulnerabilities":[{"cve":{"id":"CVE-2023-5198","sourceIdentifier":"cve@gitlab.com","published":"2023-09-29T08:15:09.610","lastModified":"2024-11-21T08:41:17.097","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab affecting all versions prior to 16.2.7, all versions starting from 16.3 before 16.3.5, and all versions starting from 16.4 before 16.4.1. It was possible for a removed project member to write to protected branches using deploy keys."},{"lang":"es","value":"Se descubrió un problema en GitLab que afecta a todas las versiones anteriores a 16.2.7, todas las versiones desde 16.3 anteriores a 16.3.5 y todas las versiones desde 16.4 anteriores a 16.4.1. Era posible que un miembro eliminado del proyecto escribiera en sucursales protegidas utilizando claves de implementación."}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-863"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"8.15","versionEndExcluding":"16.2.8","matchCriteriaId":"BDDBDB1B-AC24-4A29-BA7C-86000095393F"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"8.15","versionEndExcluding":"16.2.8","matchCriteriaId":"36F30B4B-BB02-42CF-B173-AFFC924B9965"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"50271B2B-7070-4ED0-AB68-65B99D44A68A"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"16.3.0","versionEndExcluding":"16.3.5","matchCriteriaId":"CC5696C9-592A-4D50-B5BB-9A250DAB6589"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:community:*:*:*","matchCriteriaId":"B5D4FDD1-7A68-4245-A4D5-842E4FD03FAE"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:16.4.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"6696C987-61C1-462E-8A73-016F9902BC67"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416957","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2041789","source":"cve@gitlab.com","tags":["Permissions Required"]},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/416957","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/2041789","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]}]}}]}