Total vulnerabilities in the database
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.
Software | From | Fixed in |
---|---|---|
gitlab / gitlab | 16.7.0 | 16.7.0.x |
gitlab / gitlab | 16.7.1 | 16.7.1.x |
gitlab / gitlab | 16.6.0 | 16.6.4 |
gitlab / gitlab | 8.13.0 | 16.5.6 |