An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited branch checks using a specially crafted branch name to manipulate repository content in the UI.
| Software | From | Fixed in |
|---|---|---|
| gitlab / gitlab | 16.5.0 | 16.5.3 |
| gitlab / gitlab | 16.6.0 | 16.6.0.x |
| gitlab / gitlab | - | 16.4.3 |