CVE-2023-5356: Attacker can abuse Slack/Mattermost integrations to execute slash commands as another user
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.5.6Fixed in 16.6.4Fixed in 16.7.2 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.7.2 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.6.4 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.5.6
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-5356?
CVE-2023-5356 is classified as a critical vulnerability due to its potential to allow unauthorized command execution.
What versions are affected by CVE-2023-5356?
CVE-2023-5356 affects GitLab Community and Enterprise Editions from versions 8.13 up to 16.5.6, as well as specific versions between 16.6.0 and 16.6.4 and 16.7.0 and 16.7.1.
How do I fix CVE-2023-5356?
To mitigate CVE-2023-5356, it is recommended to upgrade GitLab to version 16.5.6, 16.6.4, or 16.7.2.
What is the risk associated with CVE-2023-5356?
The risk associated with CVE-2023-5356 is that it allows attackers to execute commands on behalf of other users via Slack or Mattermost integrations.
Are there any known exploits for CVE-2023-5356?
Yes, there are reported exploits for CVE-2023-5356, indicating active attempts to leverage this vulnerability.