QID 378867
Date Published: 2023-09-20
QID 378867: Gitlab Critical Pipeline Flaw Vulnerability (CVE-2023-5009)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
Affected Versions:
GitLab versions starting from 13.12 before 16.2.7
GitLab versions starting from 16.3 before 16.3.4
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
On the vulnerable versions of GitLab, an attacker may be able to run pipelines as an arbitrary user via scheduled security scan policies.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Advisory
Vendor References
CVEs related to QID 378867
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Advisory |
|