QID 379259

Date Published: 2024-01-31

QID 379259: GitLab Multiple Security Vulnerabilities (gitlab- 15.8.2, 15.7.7 and 15.6.8)

GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software

Affected Versions:
GitLab CE/EE affecting all versions prior to 15.8.2, 15.7.7 and 15.6.8

QID Detection Logic:(Authenticated)(Linux)
The QID fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.

Successful exploitation of this vulnerability could potentially modify the metadata of signed commits.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    The vendor has released a patch for this vulnerability. For more information, please visit GitLab Releases

    CVEs related to QID 379259

    Software Advisories
    Advisory ID Software Component Link
    gitlab-15-8-2 URL Logo about.gitlab.com/releases/2023/02/14/critical-security-release-gitlab-15-8-2-released/