FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

gitlab -- privilege escalation via "impersonate" feature

Affected packages
8.2.0 <= gitlab < 8.2.5
8.3.0 <= gitlab < 8.3.9
8.4.0 <= gitlab < 8.4.10
8.5.0 <= gitlab < 8.5.12
8.6.0 <= gitlab < 8.6.8
8.7.0 <= gitlab < 8.7.1

Details

VuXML ID be72e773-1131-11e6-94fa-002590263bf5
Discovery 2016-05-02
Entry 2016-05-03

GitLab reports:

During an internal code review, we discovered a critical security flaw in the "impersonate" feature of GitLab. Added in GitLab 8.2, this feature was intended to allow an administrator to simulate being logged in as any other user.

A part of this feature was not properly secured and it was possible for any authenticated user, administrator or not, to "log in" as any other user, including administrators. Please see the issue for more details.

References

CVE Name CVE-2016-4340
FreeBSD PR ports/209225
URL https://about.gitlab.com/2016/05/02/cve-2016-4340-patches/
URL https://gitlab.com/gitlab-org/gitlab-ce/issues/15548