QID 379220
Date Published: 2024-02-14
QID 379220: GitLab Multiple Security Vulnerabilities (gitlab- 15.11.1, 15.10.5, and 15.9.6)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
Affected Versions:
GitLab CE/EE version from 11.9 prior to 15.9.6
GitLab CE/EE version from 15.10 prior to 15.10.5
GitLab CE/EE version from 15.11 prior to 15.11.1
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Security Advisory
Vendor References
- CVE-2023-1265 -
gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1265.json - GitLab Security Release: 15.11.1, 15.10.5, and 15.9.6 -
about.gitlab.com/releases/2023/05/02/security-release-gitlab-15-11-1-released/
CVEs related to QID 379220
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-1265 |
|