QID 379322
Date Published: 2024-01-30
QID 379322: GitLab Multiple Security Vulnerabilities (prior to gitlab-16.8.1, 16.7.4, 16.6.6, 16.5.8)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-6159- Arbitrary file write while creating workspace
CVE-2023-6159- ReDoS in Cargo.toml blob viewer
CVE-2024-0402- Arbitrary API PUT requests via HTML injection in username
CVE-2023-5612- Disclosure of the public email in Tags RSS Feed
CVE-2024-0456- Non-Member can update MR Assignees of owned MRs
Affected Versions:
GitLab CE/EE all versions prior to 16.5.8
GitLab CE/EE 16.6 prior to 16.6.6
GitLab CE/EE 16.7 prior to 16.7.4
GitLab CE/EE 16.8 prior to 16.8.1
QID Detection Logic:(Authenticated)(Linux)
The QID fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability allows denial of service and disclosure of sensitive information,.
- GitLab Critical Security Release: 16.8.1, 16.7.4, 16.6.6, 16.5.8 -
about.gitlab.com/releases/2024/01/25/critical-security-release-gitlab-16-8-1-released/
CVEs related to QID 379322
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| gitlab releases |
|