QID 379258
Date Published: 2024-01-16
QID 379258: GitLab EE/CE Remote Development Vulnerability (CVE-2023-6955)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-7028: Account Takeover via Password Reset without user interactions.
Affected Versions:
GitLab CE/EE affecting all versions prior to 16.5.6, 16.6 prior to 16.6.4 and 16.7 prior to 16.7.2
QID Detection Logic:(Authenticated)(Linux)
The QID fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability can lead to takeover of user accounts.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Releases
Vendor References
CVEs related to QID 379258
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-6955 |
|