NA

CVE-2016-4340

Vulnerability Summary

GitLab suffers from a privilege escalation vulnerability via the impersonate feature. Versions 8.2.0 up to and including 8.2.4, 8.3.0 up to and including 8.3.8, 8.4.0 up to and including 8.4.9, 8.5.0 up to and including 8.5.11, 8.6.0 up to and including 8.6.7, and 8.7.0 are affected.

Vendor Advisories

Debian Bug report logs - #823290 gitlab: several security issues fixed by latest version (including CVE-2016-4340) Package: gitlab; Maintainer for gitlab is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for gitlab is src:gitlab (PTS, buildd, popcon) Reported by: Paul Wise <pa ...

Exploits

GitLab suffers from a privilege escalation vulnerability via the impersonate feature Versions 820 through 824, 830 through 838, 840 through 849, 850 through 8511, 860 through 867, and 870 are affected ...