PT-2023-16848 · Gitlab · Gitlab

Joaxcaron

·

Published

2023-05-03

·

Updated

2024-03-06

·

CVE-2023-1265

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 11.9 through 15.9.6 GitLab versions 15.10 through 15.10.5 GitLab versions 15.11 through 15.11.1
Description The issue allows a privileged attacker, under certain conditions, to obtain session tokens from all users of a GitLab instance. This can be exploited by an attacker with specific privileges, potentially leading to unauthorized access to user accounts.
Recommendations For versions 11.9 through 15.9.6, update to version 15.9.6 or later. For versions 15.10 through 15.10.5, update to version 15.10.5 or later. For versions 15.11 through 15.11.1, update to version 15.11.1 or later.

Exploit

Fix

Session Fixation

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2023-1265
CVE-2023-1265

Affected Products

Gitlab