CVE Vulnerabilities

CVE-2016-4340

Published: Jan 23, 2017 | Modified: Apr 20, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to log in as any other user via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab8.2.0 (including)8.2.0 (including)
GitlabGitlab8.2.1 (including)8.2.1 (including)
GitlabGitlab8.2.2 (including)8.2.2 (including)
GitlabGitlab8.2.3 (including)8.2.3 (including)
GitlabGitlab8.2.4 (including)8.2.4 (including)
GitlabGitlab8.3.0 (including)8.3.0 (including)
GitlabGitlab8.3.1 (including)8.3.1 (including)
GitlabGitlab8.3.2 (including)8.3.2 (including)
GitlabGitlab8.3.3 (including)8.3.3 (including)
GitlabGitlab8.3.4 (including)8.3.4 (including)
GitlabGitlab8.3.5 (including)8.3.5 (including)
GitlabGitlab8.3.6 (including)8.3.6 (including)
GitlabGitlab8.3.7 (including)8.3.7 (including)
GitlabGitlab8.3.8 (including)8.3.8 (including)
GitlabGitlab8.4.0 (including)8.4.0 (including)
GitlabGitlab8.4.1 (including)8.4.1 (including)
GitlabGitlab8.4.2 (including)8.4.2 (including)
GitlabGitlab8.4.3 (including)8.4.3 (including)
GitlabGitlab8.4.4 (including)8.4.4 (including)
GitlabGitlab8.4.5 (including)8.4.5 (including)
GitlabGitlab8.4.6 (including)8.4.6 (including)
GitlabGitlab8.4.7 (including)8.4.7 (including)
GitlabGitlab8.4.8 (including)8.4.8 (including)
GitlabGitlab8.4.9 (including)8.4.9 (including)
GitlabGitlab8.5.0 (including)8.5.0 (including)
GitlabGitlab8.5.1 (including)8.5.1 (including)
GitlabGitlab8.5.2 (including)8.5.2 (including)
GitlabGitlab8.5.3 (including)8.5.3 (including)
GitlabGitlab8.5.4 (including)8.5.4 (including)
GitlabGitlab8.5.5 (including)8.5.5 (including)
GitlabGitlab8.5.6 (including)8.5.6 (including)
GitlabGitlab8.5.7 (including)8.5.7 (including)
GitlabGitlab8.5.8 (including)8.5.8 (including)
GitlabGitlab8.5.9 (including)8.5.9 (including)
GitlabGitlab8.5.10 (including)8.5.10 (including)
GitlabGitlab8.5.11 (including)8.5.11 (including)
GitlabGitlab8.6.0 (including)8.6.0 (including)
GitlabGitlab8.6.1 (including)8.6.1 (including)
GitlabGitlab8.6.2 (including)8.6.2 (including)
GitlabGitlab8.6.3 (including)8.6.3 (including)
GitlabGitlab8.6.4 (including)8.6.4 (including)
GitlabGitlab8.6.5 (including)8.6.5 (including)
GitlabGitlab8.6.6 (including)8.6.6 (including)
GitlabGitlab8.6.7 (including)8.6.7 (including)
GitlabGitlab8.7.0 (including)8.7.0 (including)
GitlabUbuntuartful*
GitlabUbuntuesm-apps/xenial*
GitlabUbuntuxenial*
GitlabUbuntuyakkety*
GitlabUbuntuzesty*

References