QID 379175

Date Published: 2024-03-28

QID 379175: GitLab CE/EE Directory Name Handling Vulnerability (CVE-2023-4522)

GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software

Affected Versions:
GitLab CE/EE version before 16.2.0

QID Detection Logic:(Authenticated)(Linux)
The QID checks the contents of /opt/gitlab/version-manifest.txt to check the vulnerable version of GitLab.

Successful exploitation of this vulnerability may affect Directory Handling error while GitLab commits.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released a patch for this vulnerability. For more information, please visit GitLab Security Advisory
    Vendor References

    CVEs related to QID 379175

    Software Advisories
    Advisory ID Software Component Link
    GitLab Security Advisory URL Logo gitlab.com/gitlab-org/gitlab/-/releases