QID 378912

Date Published: 2023-10-16

QID 378912: GitLab Multiple Security Vulnerabilities (GitLab Security Release: 16.2.2, 16.1.3, and 16.0.8)

GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software

Affected Versions:
CVE-2023-3994: Affect versions from 8.14 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-3364: Affect versions from 8.14 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-3932: Affect versions from 13.12 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-0632: Affect versions from 15.2 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-3385: Affect versions from 8.10 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-2164: Affect versions from 15.9 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-4002: Affect versions from 14.1 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-4008: Affect versions from 15.9 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-3993: Affect versions from 14.3 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-3500: Affect versions from 10.0 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-3401: Affect versions before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2.
CVE-2023-2022: Affect versions before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2
CVE-2023-1210: Affect versions from 12.9 before 16.0.8, versions from 16.1 before 16.1.3, versions from 16.2 before 16.2.2

Patch Versions:
GitLab Security Release: 16.2.2, 16.1.3, and 16.0.8

QID Detection Logic:(Authenticated)
Checks for installed vulnerable version of GitLab using command "gitlab-rake gitlab:env:info"

Successful exploitation of this vulnerabilities may affect Confidentiality, Integrity and Availability.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    The vendor has released a patch for this vulnerability. For more information, please visit GitLab Security Advisory
    Software Advisories
    Advisory ID Software Component Link
    GitLab Security Advisory URL Logo about.gitlab.com/releases/2023/08/01/security-release-gitlab-16-2-2-released/