QID 379358
Date Published: 2024-02-19
QID 379358: GitLab Multiple Security Vulnerabilities (prior to gitlab-16.8.2,16.7.5,16.6.7)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2024-1250,CVE-2023-6840-privilege escalation,
CVE-2023-6386-spike the GitLab instance resource usage resulting in service degradation,
CVE-2024-1066-resource exhaustion using GraphQL vulnerabilitiesCountByDay
Affected Versions:
GitLab CE/EE all versions from 13.3.0 prior to 16.6.7
GitLab CE/EE 16.7 prior to 16.7.5
GitLab CE/EE 16.8 prior to 16.8.2
QID Detection Logic:(Authenticated)(Linux)
The QID checks the contents of /opt/gitlab/version-manifest.txt to check the vulnerable version of GitLab.
Successful exploitation of this vulnerability allows privilege escalation and denial of service .
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Releases
Vendor References
- GitLab Critical Security Release: 16.8.2, 16.7.5, 16.6.7 -
about.gitlab.com/releases/2024/02/07/security-release-gitlab-16-8-2-released/
CVEs related to QID 379358
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Critical Security Release: 16.8.2, 16.7.5, 16.6.7 |
|