SB2017012326 - Permissions, Privileges, and Access Controls in GitLab, Gitlab Community Edition



SB2017012326 - Permissions, Privileges, and Access Controls in GitLab, Gitlab Community Edition

Published: January 23, 2017 Updated: August 9, 2020

Security Bulletin ID SB2017012326
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2016-4340)

The vulnerability allows a remote authenticated user to execute arbitrary code.

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.


Remediation

Install update from vendor's website.