First published: Fri Jan 12 2024(Updated: )
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Community Edition | =16.7.2 | |
GitLab Community Edition | =16.5.6 | |
GitLab Community Edition | =16.6.4 | |
GitLab Community Edition | =16.1.6 | |
GitLab Community Edition | =16.2.9 | |
GitLab Community Edition | =16.3.7 | |
GitLab Enterprise Edition | =16.7.2 | |
GitLab Enterprise Edition | =16.5.6 | |
GitLab Enterprise Edition | =16.6.4 | |
GitLab Enterprise Edition | =16.1.6 | |
GitLab Enterprise Edition | =16.2.9 | |
GitLab Enterprise Edition | =16.3.7 | |
>=8.13.0<16.5.6 | ||
>=8.13.0<16.5.6 | ||
>=16.6.0<16.6.4 | ||
>=16.6.0<16.6.4 | ||
=16.7.0 | ||
=16.7.0 | ||
=16.7.1 | ||
=16.7.1 |
Upgrade to versions 16.7.2, 16.6.4, 16.5.6 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.