CVE-2023-5356
Description
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.
Summary dbcve.org
Incorrect authorization checks in GitLab's slack/mattermost integration allow an authenticated user to execute slash commands as another user by abusing the integration's command processing. This is a broken access control vulnerability where the system fails to properly validate the requesting user's identity when relaying commands through external integrations.
Mitigation
Upgrade GitLab to version 16.5.6, 16.6.4, 16.7.2 or later to receive the authorization fix. Prioritize this for instances with slack/mattermost integrations enabled.