HIGH
CVE-2016-4340
CVSS
8.8
Description
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.
Weakness (CWE)
CWE-264
Permissions, Privileges & Access Controls
EPSS Score
10.14%
Probability of exploitation in next 30 days
95.4th percentile
References
http://packetstormsecurity.com/files/138368/GitLab-Impersonate-Privilege-Escalation.html
Exploit, Third Party Advisory, VDB Entry
https://about.gitlab.com/2016/05/02/cve-2016-4340-patches/
Mitigation, Patch, Vendor Advisory
https://gitlab.com/gitlab-org/gitlab-ce/issues/15548
Issue Tracking, Patch, Vendor Advisory
https://www.exploit-db.com/exploits/40236/
Exploit, Third Party Advisory, VDB Entry
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.