CyberzSOC

Publication detail
← Back to advisories & guidance

2024-007: Critical Vulnerabilities in GitLab ↗ source

January 12, 2024 CERT-EU Advisory

Summary

and Mattermost integrations to execute slash commands as another user. the required CODEOWNERS approval by adding changes to a previously approved merge Within these versions, all authentication mechanisms are impacted. Additionally, users who have two-factor authentication enabled are vulnerable to password reset but not account takeover as their second authentication factor is required to login. It is strongly recommended to upgrade all GitLab installations to one of the new versions immediately. The release also emphasises the importance of enabling Two-Factor Authentication (2FA) for additional security. At the moment, the editor did not detect any abuse of the vulnerability CVE-2023-7028 on platformsmanagedbyGitLab,including GitLab.com andGitLabDedicatedinstances. Nevertheless, regarding the self-managed instances, customers can review their logs to check for possible attempts to exploit this vulnerability: with params.value.email consisting of a JSON array with multiple email addresses. and target_details consisting of a JSON array with multiple email addresses.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2023-7028 10.0 Critical GitLab GitLab CE/EE GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails t…
CVE-2023-4812 7.6 High GitLab GitLab An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6, all versions starting from 16.6 before 16.6.4, all…
CVE-2023-5356 7.3 High GitLab GitLab Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.