QID 379547
Date Published: 2024-04-01
QID 379547: GitLab Multiple Security Vulnerabilities (prior to gitlab- 16.10.1, 16.9.3, 16.8.5)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-6371: Stored-XSS injected in Wiki page via Banzai pipeline.
CVE-2024-2818: DOS using crafted emojis.
Affected Versions:
GitLab CE/EE: all versions before 16.8.5
GitLab CE/EE: from 16.9 before 16.9.3
GitLab CE/EE: from 16.10 before 16.10.1
QID Detection Logic (Authenticated):(Linux)
The QID checks the contents of /opt/gitlab/version-manifest.txt to check the vulnerable version of GitLab.
Successful exploitation of the vulnerability may lead to Stored-XSS injected in Wiki page via Banzai pipeline and DOS using crafted emojis
Solution
GitLab has released patch addressing the vulnerability. For more information please refer to GitLab Security Release: 16.10.1, 16.9.3, 16.8.5
Vendor References
- GitLab Security Release: 16.10.1, 16.9.3, 16.8.5 -
about.gitlab.com/releases/2024/03/27/security-release-gitlab-16-10-1-released/
CVEs related to QID 379547
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Release: 16.10.1, 16.9.3, 16.8.5 |
|