VYPR
High severity7.3NVD Advisory· Published Jan 12, 2024· Updated Jun 17, 2026

CVE-2023-5356

CVE-2023-5356

Description

Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • GitLab Inc./GitLabv57 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 8.13
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=8.13.0,<16.5.6
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=8.13.0,<16.5.6
    • cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:community:*:*:*
    • cpe:2.3:a:gitlab:gitlab:16.7.0:*:*:*:enterprise:*:*:*
    • cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:community:*:*:*
    • cpe:2.3:a:gitlab:gitlab:16.7.1:*:*:*:enterprise:*:*:*
  • Range: before 16.5.6, 16.6 before 16.6.4, 16.7 before 16.7.2
  • osv-coords
    Range: >= 8.13.0, < 16.5.6

Patches

Vulnerability mechanics

References

2

News mentions

1