QID 378542

Date Published: 2023-06-05

QID 378542: GitLab Multiple Security Vulnerability (14-Feb-23)

GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software

Affected Versions:
GitLab affecting all versions before 15.8.2
GitLab affecting all versions before 15.7.7
GitLab EE affecting all versions 15.6.8
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.

Successful exploitation of the vulnerability may lead to remote code and other multiple execution.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    The vendor has released a patch for these vulnerabilities. For more information, please visit GitLab advisory

    CVEs related to QID 378542

    Software Advisories
    Advisory ID Software Component Link
    Gitlab Advisory URL Logo about.gitlab.com/releases/2023/02/14/critical-security-release-gitlab-15-8-2-released/