QID 379220

Date Published: 2024-02-14

QID 379220: GitLab Multiple Security Vulnerabilities (gitlab- 15.11.1, 15.10.5, and 15.9.6)

GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software

Affected Versions:
GitLab CE/EE version from 11.9 prior to 15.9.6
GitLab CE/EE version from 15.10 prior to 15.10.5
GitLab CE/EE version from 15.11 prior to 15.11.1

QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.

Successful exploitation of this vulnerability allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Low - 2.6 severity.
  • Solution
    The vendor has released a patch for this vulnerability. For more information, please visit GitLab Security Advisory
    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-1265 URL Logo gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-1265.json