Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    CERTFR-2023-AVI-0991

    Vulnerability from certfr_avis - Published: 2023-12-01 - Updated: 2023-12-01

    De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    GitLab N/A GitLab CE et EE versions 16.5.x antérieures à 16.5.3
    GitLab N/A GitLab CE et EE versions 16.4.x antérieures à 16.4.3
    GitLab N/A GitLab Community Edition (CE) et Enterprise Edition (EE) versions 16.6.x antérieures à 16.6.1
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "GitLab CE et EE versions 16.5.x ant\u00e9rieures \u00e0 16.5.3",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "GitLab",
              "scada": false
            }
          }
        },
        {
          "description": "GitLab CE et EE versions 16.4.x ant\u00e9rieures \u00e0 16.4.3",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "GitLab",
              "scada": false
            }
          }
        },
        {
          "description": "GitLab Community Edition (CE) et Enterprise Edition (EE) versions 16.6.x ant\u00e9rieures \u00e0 16.6.1",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "GitLab",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-4317",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4317"
        },
        {
          "name": "CVE-2022-41409",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41409"
        },
        {
          "name": "CVE-2023-3401",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3401"
        },
        {
          "name": "CVE-2023-39417",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-39417"
        },
        {
          "name": "CVE-2023-6033",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-6033"
        },
        {
          "name": "CVE-2023-5995",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-5995"
        },
        {
          "name": "CVE-2023-3443",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3443"
        },
        {
          "name": "CVE-2023-5226",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-5226"
        },
        {
          "name": "CVE-2023-6396",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-6396"
        },
        {
          "name": "CVE-2023-4912",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4912"
        },
        {
          "name": "CVE-2023-3964",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3964"
        },
        {
          "name": "CVE-2023-4658",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-4658"
        },
        {
          "name": "CVE-2023-3949",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-3949"
        }
      ],
      "initial_release_date": "2023-12-01T00:00:00",
      "last_revision_date": "2023-12-01T00:00:00",
      "links": [],
      "reference": "CERTFR-2023-AVI-0991",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-12-01T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Injection de code indirecte \u00e0 distance (XSS)"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans \u003cspan\nclass=\"textit\"\u003eGitLab\u003c/span\u003e. Certaines d\u0027entre elles permettent \u00e0 un\nattaquant de provoquer une \u00e9l\u00e9vation de privil\u00e8ges, une atteinte \u00e0\nl\u0027int\u00e9grit\u00e9 des donn\u00e9es et une atteinte \u00e0 la confidentialit\u00e9 des\ndonn\u00e9es.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans GitLab",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 GitLab du 30 novembre 2023",
          "url": "https://about.gitlab.com/releases/2023/11/30/security-release-gitlab-16-6-1-released/"
        }
      ]
    }

    GSD-2023-6396

    Vulnerability from gsd - Updated: 2023-12-13 01:20
    Details
    ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
    Aliases
    Aliases

    {
      "GSD": {
        "alias": "CVE-2023-6396",
        "id": "GSD-2023-6396"
      },
      "gsd": {
        "metadata": {
          "exploitCode": "unknown",
          "remediation": "unknown",
          "reportConfidence": "confirmed",
          "type": "vulnerability"
        },
        "osvSchema": {
          "aliases": [
            "CVE-2023-6396"
          ],
          "id": "GSD-2023-6396",
          "modified": "2023-12-13T01:20:32.617544Z",
          "schema_version": "1.4.0"
        }
      },
      "namespaces": {
        "cve.org": {
          "CVE_data_meta": {
            "ASSIGNER": "cve@mitre.org",
            "ID": "CVE-2023-6396",
            "STATE": "RESERVED"
          },
          "data_format": "MITRE",
          "data_type": "CVE",
          "data_version": "4.0",
          "description": {
            "description_data": [
              {
                "lang": "eng",
                "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
              }
            ]
          }
        }
      }
    }

    UBUNTU-CVE-2023-6396 (CVE-2023-6396)

    Vulnerability from osv_ubuntu – Published: 2023-12-04 00:00 – Updated: 2025-10-24 05:01 – Source website
    VLAI
    Details

    [Unknown description]

    Severity
    N/A (UNKNOWN)

    {
      "affected": [
        {
          "ecosystem_specific": {
            "binaries": [
              {
                "binary_name": "gitlab",
                "binary_version": "8.5.8+dfsg-5"
              }
            ]
          },
          "package": {
            "ecosystem": "Ubuntu:16.04:LTS",
            "name": "gitlab",
            "purl": "pkg:deb/ubuntu/gitlab@8.5.8+dfsg-5?arch=source\u0026distro=xenial"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ],
          "versions": [
            "8.4.3+dfsg-9",
            "8.4.3+dfsg-12",
            "8.5.8+dfsg-5"
          ]
        }
      ],
      "aliases": [],
      "details": "[Unknown description]",
      "id": "UBUNTU-CVE-2023-6396",
      "modified": "2025-10-24T05:01:39Z",
      "published": "2023-12-04T00:00:00Z",
      "references": [
        {
          "type": "REPORT",
          "url": "https://ubuntu.com/security/CVE-2023-6396"
        },
        {
          "type": "REPORT",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-6396"
        }
      ],
      "related": [],
      "schema_version": "1.7.0",
      "severity": [
        {
          "score": "medium",
          "type": "Ubuntu"
        }
      ],
      "upstream": [
        "CVE-2023-6396"
      ]
    }

    WID-SEC-W-2023-3041

    Vulnerability from csaf_certbund - Published: 2023-11-30 23:00 - Updated: 2026-02-03 23:00
    Summary
    GitLab: Mehrere Schwachstellen
    Severity
    Hoch
    Scope
    13 vulnerabilities in this advisory, including CVE-2023-6396.
    CVE-2023-6396
    Known affected: 4 products
    Open the full advisory