High severity7.3NVD Advisory· Published Jan 12, 2024· Updated Jun 17, 2026
CVE-2023-5356
CVE-2023-5356
Description
Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 8.13
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=8.13.0,<16.5.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.13.0,<16.5.6
- cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:enterprise:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:enterprise:*:*:*
- Range: before 16.5.6, 16.6 before 16.6.4, 16.7 before 16.7.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/427154nvdBroken Link
- hackerone.com/reports/2188868nvdPermissions Required
News mentions
1- GitLab Critical Security Release: 16.7.2, 16.6.4, 16.5.6GitLab Security Releases · Jan 11, 2024