HIGH

CVE-2023-5356

Gitlab GitLab 2024-01-12 CVSS v3.1
CVSS
8.8

Description

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

Summary dbcve.org

Incorrect authorization checks in GitLab's slack/mattermost integration allow an authenticated user to execute slash commands as another user by abusing the integration's command processing. This is a broken access control vulnerability where the system fails to properly validate the requesting user's identity when relaying commands through external integrations.

Mitigation

Upgrade GitLab to version 16.5.6, 16.6.4, 16.7.2 or later to receive the authorization fix. Prioritize this for instances with slack/mattermost integrations enabled.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.83%
Probability of exploitation in next 30 days
55.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE