CVE-2016-4340
GitLab - 'impersonate' Feature Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.
La característica de suplantación en Gitlab 8.7.0, 8.6.0 hasta la versión 8.6.7, 8.5.0 hasta la versión 8.5.11, 8.4.0 hasta la versión 8.4.9, 8.3.0 hasta la versión 8.3.8 y 8.2.0 hasta la versión 8.2.4 permite a usuarios remotos autenticados para "iniciar sesión" como cualquier otro usuario a través de vectores no especificados.
GitLab suffers from a privilege escalation vulnerability via the impersonate feature. Versions 8.2.0 through 8.2.4, 8.3.0 through 8.3.8, 8.4.0 through 8.4.9, 8.5.0 through 8.5.11, 8.6.0 through 8.6.7, and 8.7.0 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-04-27 CVE Reserved
- 2016-08-16 CVE Published
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- 2025-01-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/40236 | 2024-08-06 | |
http://packetstormsecurity.com/files/138368/GitLab-Impersonate-Privilege-Escalation.html | 2024-08-06 |
URL | Date | SRC |
---|---|---|
https://about.gitlab.com/2016/05/02/cve-2016-4340-patches | 2017-01-25 | |
https://gitlab.com/gitlab-org/gitlab-ce/issues/15548 | 2017-01-25 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.2.0 Search vendor "Gitlab" for product "Gitlab" and version "8.2.0" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.2.1 Search vendor "Gitlab" for product "Gitlab" and version "8.2.1" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.2.2 Search vendor "Gitlab" for product "Gitlab" and version "8.2.2" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.2.3 Search vendor "Gitlab" for product "Gitlab" and version "8.2.3" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.2.4 Search vendor "Gitlab" for product "Gitlab" and version "8.2.4" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.3.0 Search vendor "Gitlab" for product "Gitlab" and version "8.3.0" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.3.1 Search vendor "Gitlab" for product "Gitlab" and version "8.3.1" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.3.2 Search vendor "Gitlab" for product "Gitlab" and version "8.3.2" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.3.3 Search vendor "Gitlab" for product "Gitlab" and version "8.3.3" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.3.4 Search vendor "Gitlab" for product "Gitlab" and version "8.3.4" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.3.5 Search vendor "Gitlab" for product "Gitlab" and version "8.3.5" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.3.6 Search vendor "Gitlab" for product "Gitlab" and version "8.3.6" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.3.7 Search vendor "Gitlab" for product "Gitlab" and version "8.3.7" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.3.8 Search vendor "Gitlab" for product "Gitlab" and version "8.3.8" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.4.0 Search vendor "Gitlab" for product "Gitlab" and version "8.4.0" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.4.1 Search vendor "Gitlab" for product "Gitlab" and version "8.4.1" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.4.2 Search vendor "Gitlab" for product "Gitlab" and version "8.4.2" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.4.3 Search vendor "Gitlab" for product "Gitlab" and version "8.4.3" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.4.4 Search vendor "Gitlab" for product "Gitlab" and version "8.4.4" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.4.5 Search vendor "Gitlab" for product "Gitlab" and version "8.4.5" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.4.6 Search vendor "Gitlab" for product "Gitlab" and version "8.4.6" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.4.7 Search vendor "Gitlab" for product "Gitlab" and version "8.4.7" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.4.8 Search vendor "Gitlab" for product "Gitlab" and version "8.4.8" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.4.9 Search vendor "Gitlab" for product "Gitlab" and version "8.4.9" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.0 Search vendor "Gitlab" for product "Gitlab" and version "8.5.0" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.1 Search vendor "Gitlab" for product "Gitlab" and version "8.5.1" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.2 Search vendor "Gitlab" for product "Gitlab" and version "8.5.2" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.3 Search vendor "Gitlab" for product "Gitlab" and version "8.5.3" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.4 Search vendor "Gitlab" for product "Gitlab" and version "8.5.4" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.5 Search vendor "Gitlab" for product "Gitlab" and version "8.5.5" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.6 Search vendor "Gitlab" for product "Gitlab" and version "8.5.6" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.7 Search vendor "Gitlab" for product "Gitlab" and version "8.5.7" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.8 Search vendor "Gitlab" for product "Gitlab" and version "8.5.8" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.9 Search vendor "Gitlab" for product "Gitlab" and version "8.5.9" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.10 Search vendor "Gitlab" for product "Gitlab" and version "8.5.10" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.5.11 Search vendor "Gitlab" for product "Gitlab" and version "8.5.11" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.6.0 Search vendor "Gitlab" for product "Gitlab" and version "8.6.0" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.6.1 Search vendor "Gitlab" for product "Gitlab" and version "8.6.1" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.6.2 Search vendor "Gitlab" for product "Gitlab" and version "8.6.2" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.6.3 Search vendor "Gitlab" for product "Gitlab" and version "8.6.3" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.6.4 Search vendor "Gitlab" for product "Gitlab" and version "8.6.4" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.6.5 Search vendor "Gitlab" for product "Gitlab" and version "8.6.5" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.6.6 Search vendor "Gitlab" for product "Gitlab" and version "8.6.6" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.6.7 Search vendor "Gitlab" for product "Gitlab" and version "8.6.7" | - |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 8.7.0 Search vendor "Gitlab" for product "Gitlab" and version "8.7.0" | - |
Affected
|