QID 379154
Date Published: 2024-01-02
QID 379154: GitLab Multiple Security Vulnerabilities (GitLab Security Release: 16.6.2, 16.5.4, 16.4.4)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
Affected Versions:
CVE-2023-6680:GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2
CVE-2023-6564:GitLab EE Premium and Ultimate affecting versions 16.4.3, 16.5.3, and 16.6.1
CVE-2023-6051:GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 15.5 before 16.5.4, all versions starting from 16.6 before 16.6.2
CVE-2023-3907:GitLab EE affecting all versions from 16.0 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2
CVE-2023-5512:GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2
CVE-2023-3904:GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2
CVE-2023-5061:GitLab affecting all versions starting from 9.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2
CVE-2023-3511:GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2
Patch Versions:
GitLab Security Release: 16.6.2, 16.5.4, 16.4.4
QID Detection Logic:(Authenticated)
Checks for installed vulnerable version of GitLab using command "gitlab-rake gitlab:env:info"
Successful exploitation of this vulnerabilities may affect Confidentiality, Integrity and Availability.
- GitLab Security Advisory -
about.gitlab.com/releases/2023/12/13/security-release-gitlab-16-6-2-released/
CVEs related to QID 379154
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Advisory |
|