QID 379225
QID 379225: GitLab CE/EE Time-of-check time-of-use (toctou) Race Condition Vulnerability (CVE-2023-1265)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
Affected Versions:
GitLab CE/EE all versions starting from 15.7 before 15.8.5, from 15.9 before 15.9.4, and from 15.10 before 15.10.1
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability allows for a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Security Advisory
Vendor References
- CVE-2022-4143 -
gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4143.json
CVEs related to QID 379225
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-4143 |
|