QID 379608
QID 379608: Gitlab A user can change the name and path of some public GitLab groups Vulnerability (prior to gitlab- 16.1.2, 16.0.7, 15.11.11)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-3484: A user can change the name and path of some public GitLab groups
Affected Versions:
16.1.0, 16.1.1, 16.0.0, 16.0.1, 16.0.2, 16.0.3, 16.0.4, 16.0.5, 16.0.6, 15.11.0, 15.11.1, 15.11.2, 15.11.3, 15.11.4, 15.11.5, 15.11.6, 15.11.7, 15.11.8, 15.11.9, 15.11.10, and below
QID Detection Logic (Authenticated):(Linux)
The QID checks the contents of /opt/gitlab/version-manifest.txt to check the vulnerable version of GitLab.
Successful exploitation of the vulnerability may lead to A user can change the name and path of some public GitLab groups
Solution
GitLab has released patch addressing the vulnerability. For more information please refer to GitLab Security Release: 16.1.2, 16.0.7, and 15.11.11
Vendor References
- GitLab Security Release: 16.1.2, 16.0.7, and 15.11.11 -
about.gitlab.com/releases/2023/07/05/security-release-gitlab-16-1-2-released/
CVEs related to QID 379608
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Release: 16.1.2, 16.0.7, and 15.11.11 |
|