655
VMScore

CVE-2016-4340

Published: 23/01/2017 Updated: 25/01/2017
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The impersonate feature in Gitlab 8.7.0, 8.6.0 up to and including 8.6.7, 8.5.0 up to and including 8.5.11, 8.4.0 up to and including 8.4.9, 8.3.0 up to and including 8.3.8, and 8.2.0 up to and including 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab 8.3.4

gitlab gitlab 8.3.5

gitlab gitlab 8.3.6

gitlab gitlab 8.3.7

gitlab gitlab 8.5.2

gitlab gitlab 8.5.3

gitlab gitlab 8.5.4

gitlab gitlab 8.5.5

gitlab gitlab 8.6.7

gitlab gitlab 8.7.0

gitlab gitlab 8.2.1

gitlab gitlab 8.2.2

gitlab gitlab 8.2.3

gitlab gitlab 8.2.4

gitlab gitlab 8.4.4

gitlab gitlab 8.4.5

gitlab gitlab 8.4.6

gitlab gitlab 8.4.7

gitlab gitlab 8.5.10

gitlab gitlab 8.5.11

gitlab gitlab 8.6.0

gitlab gitlab 8.6.1

gitlab gitlab 8.2.0

gitlab gitlab 8.3.0

gitlab gitlab 8.3.2

gitlab gitlab 8.4.0

gitlab gitlab 8.4.2

gitlab gitlab 8.4.9

gitlab gitlab 8.5.1

gitlab gitlab 8.5.6

gitlab gitlab 8.5.8

gitlab gitlab 8.6.3

gitlab gitlab 8.6.5

gitlab gitlab 8.3.1

gitlab gitlab 8.3.3

gitlab gitlab 8.3.8

gitlab gitlab 8.4.1

gitlab gitlab 8.4.3

gitlab gitlab 8.4.8

gitlab gitlab 8.5.0

gitlab gitlab 8.5.7

gitlab gitlab 8.5.9

gitlab gitlab 8.6.2

gitlab gitlab 8.6.4

gitlab gitlab 8.6.6

Vendor Advisories

Debian Bug report logs - #823290 gitlab: several security issues fixed by latest version (including CVE-2016-4340) Package: gitlab; Maintainer for gitlab is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for gitlab is src:gitlab (PTS, buildd, popcon) Reported by: Paul Wise <pa ...

Exploits

# Exploit Title: GitLab privilege escalation via "impersonate" feature # Date: 02-05-2016 # Software Link: aboutgitlabcom/ # Version: 820 - 824, 830 - 838, 840 - 849, 850 - 8511, 860 - 867, 870 # Exploit Author: Kaimi # Website: kaimiru # CVE: CVE-2016-4340 # Category: webapps 1 Description Any regist ...
GitLab suffers from a privilege escalation vulnerability via the impersonate feature Versions 820 through 824, 830 through 838, 840 through 849, 850 through 8511, 860 through 867, and 870 are affected ...