QID 379589
QID 379589: Gitlab Multiple Vulnerabilities (prior to gitlab- 16.0.2, 15.11.7, 15.10.8)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-2442: Stored-XSS with CSP-bypass in Merge requests
CVE-2023-2199: ReDoS via FrontMatterFilter in any Markdown fields
CVE-2023-2198: ReDoS via InlineDiffFilter in any Markdown fields
CVE-2023-2132: ReDoS via DollarMathPostFilter in Markdown fields
CVE-2023-0121: DoS via malicious test report artifacts
CVE-2023-2589: Restricted IP addresses can clone repositories of public projects
CVE-2023-2015: Reflected XSS in Report Abuse Functionality
CVE-2023-2485: Privilege escalation from maintainer to owner by importing members from a project
CVE-2023-2001: Bypassing tags protection in GitLab
CVE-2023-0921: Denial of Service using multiple labels with arbitrarily large descriptions
CVE-2023-1204: Ability to use an unverified email for public and commit emails
CVE-2023-0508: Open Redirection Through HTTP Response Splitting
CVE-2023-1825: Disclosure of issue notes to an unauthorized user when exporting a project
CVE-2023-2013: Ambiguous branch name exploitation
Affected Versions:
16.0.0, 16.0.1, 15.11.0, 15.11.1, 15.11.2, 15.11.3, 15.11.4, 15.11.5, 15.11.6, 15.10.0, 15.10.1, 15.10.2, 15.10.3, 15.10.4, 15.10.5, 15.10.6, 15.10.7, and below
QID Detection Logic (Authenticated):(Linux)
The QID checks the contents of /opt/gitlab/version-manifest.txt to check the vulnerable version of GitLab.
Successful exploitation of the vulnerability may lead to Stored-XSS with CSP-bypass in Merge requests, ReDoS via FrontMatterFilter in any Markdown fields, ReDoS via InlineDiffFilter in any Markdown fields, ReDoS via DollarMathPostFilter in Markdown fields, DoS via malicious test report artifacts, Restricted IP addresses can clone repositories of public projects, Reflected XSS in Report Abuse Functionality, Privilege escalation from maintainer to owner by importing members from a project, Bypassing tags protection in GitLab, Denial of Service using multiple labels with arbitrarily large descriptions, Ability to use an unverified email for public and commit emails, Open Redirection Through HTTP Response Splitting, Disclosure of issue notes to an unauthorized user when exporting a project, Ambiguous branch name exploitation
- GitLab Security Release: 16.0.2, 15.11.7, and 15.10.8 -
about.gitlab.com/releases/2023/06/05/security-release-gitlab-16-0-2-released/
CVEs related to QID 379589
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Release: 16.0.2, 15.11.7, and 15.10.8 |
|