First published: Mon Jan 23 2017(Updated: )
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | =8.2.0 | |
GitLab | =8.2.1 | |
GitLab | =8.2.2 | |
GitLab | =8.2.3 | |
GitLab | =8.2.4 | |
GitLab | =8.3.0 | |
GitLab | =8.3.1 | |
GitLab | =8.3.2 | |
GitLab | =8.3.3 | |
GitLab | =8.3.4 | |
GitLab | =8.3.5 | |
GitLab | =8.3.6 | |
GitLab | =8.3.7 | |
GitLab | =8.3.8 | |
GitLab | =8.4.0 | |
GitLab | =8.4.1 | |
GitLab | =8.4.2 | |
GitLab | =8.4.3 | |
GitLab | =8.4.4 | |
GitLab | =8.4.5 | |
GitLab | =8.4.6 | |
GitLab | =8.4.7 | |
GitLab | =8.4.8 | |
GitLab | =8.4.9 | |
GitLab | =8.5.0 | |
GitLab | =8.5.1 | |
GitLab | =8.5.2 | |
GitLab | =8.5.3 | |
GitLab | =8.5.4 | |
GitLab | =8.5.5 | |
GitLab | =8.5.6 | |
GitLab | =8.5.7 | |
GitLab | =8.5.8 | |
GitLab | =8.5.9 | |
GitLab | =8.5.10 | |
GitLab | =8.5.11 | |
GitLab | =8.6.0 | |
GitLab | =8.6.1 | |
GitLab | =8.6.2 | |
GitLab | =8.6.3 | |
GitLab | =8.6.4 | |
GitLab | =8.6.5 | |
GitLab | =8.6.6 | |
GitLab | =8.6.7 | |
GitLab | =8.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4340 is classified as a high severity vulnerability due to the potential for unauthorized account access.
To fix CVE-2016-4340, upgrade GitLab to version 8.7.1 or later, or apply the appropriate patches.
CVE-2016-4340 affects GitLab versions 8.2.0 through 8.7.0, allowing remote authenticated users to impersonate other users.
Systems running GitLab versions between 8.2.0 and 8.7.0 are at risk due to the impersonation vulnerability.
Exploiting CVE-2016-4340 can lead to unauthorized access to user accounts, compromising sensitive data and security.