vulnerability
FreeBSD: gitlab -- privilege escalation via "impersonate" feature (CVE-2016-4340)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:L/Au:S/C:P/I:P/A:P) | May 2, 2016 | May 4, 2016 | Oct 30, 2017 |
Severity
7
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:P)
Published
May 2, 2016
Added
May 4, 2016
Modified
Oct 30, 2017
Description
GitLab reports:
During an internal code review, we discovered a critical security
flaw in the "impersonate" feature of GitLab. Added in GitLab 8.2,
this feature was intended to allow an administrator to simulate
being logged in as any other user.
A part of this feature was not properly secured and it was possible
for any authenticated user, administrator or not, to "log in" as any
other user, including administrators. Please see the issue for more
details.
Solution
freebsd-upgrade-package-gitlab
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.