QID 379583
QID 379583: Gitlab Smuggling code changes via merge requests with refs/replace Vulnerability (prior to gitlab- 15.11.3, 15.10.7, 15.9.8)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-2181: Smuggling code changes via merge requests with refs/replace
Affected Versions:
15.11.0, 15.11.1, 15.11.2, 15.10.0, 15.10.1, 15.10.2, 15.10.3, 15.10.4, 15.10.5, 15.10.6, 15.9.0, 15.9.1, 15.9.2, 15.9.3, 15.9.4, 15.9.5, 15.9.6, 15.9.7, and below
QID Detection Logic (Authenticated):(Linux)
The QID checks the contents of /opt/gitlab/version-manifest.txt to check the vulnerable version of GitLab.
Successful exploitation of the vulnerability may lead to Smuggling code changes via merge requests with refs/replace
Solution
GitLab has released patch addressing the vulnerability. For more information please refer to GitLab Coordinated Security Release: 15.11.3, 15.10.7, 15.9.8
Vendor References
- GitLab Coordinated Security Release: 15.11.3, 15.10.7, 15.9.8 -
about.gitlab.com/releases/2023/05/10/security-release-gitlab-15-11-3-released/
CVEs related to QID 379583
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Coordinated Security Release: 15.11.3, 15.10.7, 15.9.8 |
|