QID 379480
Date Published: 2024-03-20
QID 379480: GitLab Multiple Security Vulnerabilities (prior to gitlab-16.9.2, 16.8.4, 16.7.7)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2024-0199: Bypassing CODEOWNERS approval allowing to steal protected variables.
CVE-2024-1299: Guest with manage group access tokens can rotate and see group access token with owner permissions.
Affected Versions:
GitLab CE/EE all versions starting from v11.3 prior to patched versions: v16.7.7, v16.8.4, v16.9.2.
QID Detection Logic:(Authenticated)(Linux)
The QID checks the contents of /opt/gitlab/version-manifest.txt to check the vulnerable version of GitLab.
Successful exploitation of this vulnerability affects confidentiality, integrity and availability.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Releases
Vendor References
- GitLab Security Release: 16.9.2, 16.8.4, 16.7.7 -
about.gitlab.com/releases/2024/03/06/security-release-gitlab-16-9-2-released/#guest-with-manage-group-access-tokens-can-rotate-and-see-group-access-token-with-owner-permissions
CVEs related to QID 379480
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Release: 16.9.2, 16.8.4, 16.7.7 |
|