Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    CERTFR-2023-AVI-0707

    Vulnerability from certfr_avis - Published: 2023-09-01 - Updated: 2023-09-01

    De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer un contournement de la politique de sécurité, une atteinte à la confidentialité des données et une élévation de privilèges.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    GitLab N/A GitLab Enterprise Edition (EE) versions 16.2.x antérieures à 16.2.5
    GitLab N/A GitLab Enterprise Edition (EE) versions 16.1.x antérieures à 16.1.5
    GitLab N/A GitLab Community Edition (CE) versions 16.3.x antérieures à 16.3.1
    GitLab N/A GitLab Community Edition (CE) versions 16.1.x antérieures à 16.1.5
    GitLab N/A GitLab Community Edition (CE) versions 16.2.x antérieures à 16.2.5
    GitLab N/A GitLab Enterprise Edition (EE) versions 16.3.x antérieures à 16.3.1

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "GitLab Enterprise Edition (EE) versions 16.2.x ant\u00e9rieures \u00e0 16.2.5",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "GitLab",
              "scada": false
            }
          }
        },
        {
          "description": "GitLab Enterprise Edition (EE) versions 16.1.x ant\u00e9rieures \u00e0 16.1.5",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "GitLab",
              "scada": false
            }
          }
        },
        {
          "description": "GitLab Community Edition (CE) versions 16.3.x ant\u00e9rieures \u00e0 16.3.1",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "GitLab",
              "scada": false
            }
          }
        },
        {
          "description": "GitLab Community Edition (CE) versions 16.1.x ant\u00e9rieures \u00e0 16.1.5",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "GitLab",
              "scada": false
            }
          }
        },
        {
          "description": "GitLab Community Edition (CE) versions 16.2.x ant\u00e9rieures \u00e0 16.2.5",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "GitLab",
              "scada": false
            }
          }
        },
        {
          "description": "GitLab Enterprise Edition (EE) versions 16.3.x ant\u00e9rieures \u00e0 16.3.1",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "GitLab",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-4378",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4378"
        },
        {
          "name": "CVE-2023-4018",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4018"
        },
        {
          "name": "CVE-2023-3205",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3205"
        },
        {
          "name": "CVE-2023-1279",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-1279"
        },
        {
          "name": "CVE-2022-4343",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-4343"
        },
        {
          "name": "CVE-2023-3950",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3950"
        },
        {
          "name": "CVE-2023-1555",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-1555"
        },
        {
          "name": "CVE-2023-0120",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-0120"
        },
        {
          "name": "CVE-2022-4365",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-4365"
        },
        {
          "name": "CVE-2023-4630",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4630"
        },
        {
          "name": "CVE-2023-3915",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3915"
        },
        {
          "name": "CVE-2023-4638",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4638"
        },
        {
          "name": "CVE-2023-4647",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4647"
        }
      ],
      "initial_release_date": "2023-09-01T00:00:00",
      "last_revision_date": "2023-09-01T00:00:00",
      "links": [
        {
          "title": "Bulletin de s\u00e9curit\u00e9 GitLab\u00a0security-release-gitlab-16-3-1-released du 31 ao\u00fbt 2023",
          "url": "https://about.gitlab.com/releases/2023/08/31/security-release-gitlab-16-3-1-released/"
        }
      ],
      "reference": "CERTFR-2023-AVI-0707",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-09-01T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "D\u00e9ni de service"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans \u003cspan\nclass=\"textit\"\u003eGitLab\u003c/span\u003e. Certaines d\u0027entre elles permettent \u00e0 un\nattaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9, une\natteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es et une \u00e9l\u00e9vation de\nprivil\u00e8ges.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans GitLab",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 GitLab security-release-gitlab-16-3-1-released du 31 ao\u00fbt 2023",
          "url": null
        }
      ]
    }

    GSD-2023-4638

    Vulnerability from gsd - Updated: 2023-12-13 01:20
    Details
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    Aliases
    Aliases

    {
      "GSD": {
        "alias": "CVE-2023-4638",
        "id": "GSD-2023-4638"
      },
      "gsd": {
        "metadata": {
          "exploitCode": "unknown",
          "remediation": "unknown",
          "reportConfidence": "confirmed",
          "type": "vulnerability"
        },
        "osvSchema": {
          "aliases": [
            "CVE-2023-4638"
          ],
          "id": "GSD-2023-4638",
          "modified": "2023-12-13T01:20:26.722468Z",
          "schema_version": "1.4.0"
        }
      },
      "namespaces": {
        "cve.org": {
          "CVE_data_meta": {
            "ASSIGNER": "cve@mitre.org",
            "ID": "CVE-2023-4638",
            "STATE": "RESERVED"
          },
          "data_format": "MITRE",
          "data_type": "CVE",
          "data_version": "4.0",
          "description": {
            "description_data": [
              {
                "lang": "eng",
                "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
              }
            ]
          }
        }
      }
    }

    UBUNTU-CVE-2023-4638 (CVE-2023-4638)

    Vulnerability from osv_ubuntu – Published: 2023-09-11 00:00 – Updated: 2025-10-24 05:01 – Source website
    VLAI
    Details

    [Unknown description]

    Severity
    N/A (UNKNOWN)

    {
      "affected": [
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "gitlab",
                "binary_version": "8.5.8+dfsg-5"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:16.04:LTS",
            "name": "gitlab",
            "purl": "pkg:deb/ubuntu/gitlab@8.5.8+dfsg-5?arch=source\u0026distro=xenial"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "8.4.3+dfsg-9",
            "8.4.3+dfsg-12",
            "8.5.8+dfsg-5"
          ]
        }
      ],
      "aliases": [],
      "details": "[Unknown description]",
      "id": "UBUNTU-CVE-2023-4638",
      "modified": "2025-10-24T05:01:34Z",
      "published": "2023-09-11T00:00:00Z",
      "references": [
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2023-4638"
        },
        {
          "type": "REPORT",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4638"
        }
      ],
      "related": [],
      "schema_version": "1.7.0",
      "severity": [
        {
          "score": "medium",
          "type": "Ubuntu"
        }
      ],
      "upstream": [
        "CVE-2023-4638"
      ]
    }

    WID-SEC-W-2023-2244

    Vulnerability from csaf_certbund - Published: 2023-08-31 22:00 - Updated: 2023-09-03 22:00
    Summary
    GitLab: Mehrere Schwachstellen
    Severity
    Mittel
    Scope
    13 vulnerabilities in this advisory, including CVE-2023-4638.
    CVE-2023-4638
    Open the full advisory