QID 379245
Date Published: 2024-01-12
QID 379245: GitLab EE/CE Command Execution Vulnerability (CVE-2023-5356)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-5356: Incorrect authorization checks in GitLab CE/EE allows a attacker/user to abuse Slack/Mattermost integrations to execute slash commands as another user.
Affected Versions:
GitLab CE/EE v8.13 before 16.5.6, v16.6 before 16.6.4
QID Detection Logic:(Authenticated)(Linux)
The QID fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability allows a user to abuse Slack/Mattermost integrations to execute slash commands as another user.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Releases
Vendor References
CVEs related to QID 379245
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-5356. |
|