An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/421607 |
History
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2023-12-15T16:02:40.371Z
Updated: 2024-08-29T15:04:53.061Z
Reserved: 2023-12-11T12:30:49.713Z
Link: CVE-2023-6680
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-12-15T16:15:46.737
Modified: 2024-11-21T08:44:19.957
Link: CVE-2023-6680
Redhat
No data.