« Volver al listado

CVE-2023-5356

Estado: ModificadaAlta (8.8)—

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-5356",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-5356",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-01-23T21:57:40.489112Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve@gitlab.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@gitlab.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"
          ],
          "repo": "git://git@gitlab.com:gitlab-org/gitlab.git",
          "vendor": "GitLab",
          "product": "GitLab",
          "versions": [
            {
              "status": "affected",
              "version": "8.13",
              "lessThan": "16.5.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "16.6",
              "lessThan": "16.6.4",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "16.7",
              "lessThan": "16.7.2",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-01-12T14:15:48.707",
  "references": [
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/427154",
      "tags": [
        "Broken Link"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://hackerone.com/reports/2188868",
      "tags": [
        "Permissions Required"
      ],
      "source": "cve@gitlab.com"
    },
    {
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/427154",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://hackerone.com/reports/2188868",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve@gitlab.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user."
    },
    {
      "lang": "es",
      "value": "Verificaciones de autorización incorrectas en GitLab CE/EE desde todas las versiones desde 8.13 anteriores a 16.5.6, todas las versiones desde 16.6 anteriores a 16.6.4, todas las versiones desde 16.7 anteriores a 16.7.2, permiten que un usuario abuse de las integraciones de slack/mattermost para ejecutar slash commands como otro usuario."
    }
  ],
  "lastModified": "2026-06-17T06:48:24.947",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0266465-DBD2-4133-90B2-8DAE8D5C8588",
              "versionEndExcluding": "16.5.6",
              "versionStartIncluding": "8.13.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "75FBB40A-5B80-4CCC-81A1-B134B9529A23",
              "versionEndExcluding": "16.5.6",
              "versionStartIncluding": "8.13.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7198B7E4-9928-4B7D-9D00-6B76CCAC3875",
              "versionEndExcluding": "16.6.4",
              "versionStartIncluding": "16.6.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D294EA47-B2EF-42D6-A92B-93CEA5D209B7",
              "versionEndExcluding": "16.6.4",
              "versionStartIncluding": "16.6.0"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "150F88EA-DA27-4042-9778-932904C2FD41"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29C6355F-1CD3-4E4A-AACA-19B497A631D6"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:community:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D385A20C-BC93-4BB9-A47D-50C89D4DFA95"
            },
            {
              "criteria": "cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:enterprise:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77D86BC4-D4DD-4848-B0FD-0C16A3D2DF89"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@gitlab.com"
}