GitLab users told to install emergency security fix immediately
GitLab has released a fix for a newly discovered security flaw, and is urging its users to install immediately as it addresses a high-severity vulnerability that can cause all sorts of trouble.
In a security bulletin, GitLab said an attacker could abuse scan execution policies to run pipelines (a series of automated tasks) as another user.
This flaw is now tracked as CVE-2023-4998 and carries a severity score of 9.6. It impacts a couple of versions of the software, namely GitLab Community Edition (CE) and Enterprise Edition (EE) versions 13.12 through 16.2.7, and versions 16.3 through 16.3.4.
According to a BleepingComputer report, a threat actor could impersonate a user without their knowledge and permission, and access sensitive information or run malicious code, modify data, or trigger specific events within the GitLab system. Given that GitLab is a code management platform, the vulnerability could lead to intellectual property theft, data leaks, supply chain attacks, and more, the publication claims.
Fixes and workarounds
According to a BleepingComputer report, a threat actor could impersonate a user without their knowledge and permission, and access sensitive information or run malicious code, modify data, or trigger specific events within the GitLab system. Given that GitLab is a code management platform, the vulnerability could lead to intellectual property theft, data leaks, supply chain attacks, and more, the publication claims.
“We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possible,” GitLab said in the advisory.
The vulnerability, discovered by security researcher Johan Carlsson, actually stems from a previous flaw that apparently wasn’t properly addressed. Last month, a vulnerability tracked as VE-2023-3932 was found and patched. Back then, it was a medium-severity flaw. However, Carlsson found a way to work around the fix, and even discovered that the new flaw carries even more weight (hence the new severity score of 9.6).
Users who run GitLab versions older than 16.2 should make sure they don’t have “Direct transfers” and “Security policies” both turned on, as that will make the endpoint vulnerable. Users should have just one turned at any point in time, the advisory said.
GitLab can be updated via GitLab Runner packages from the official website.
More from TechRadar Pro
GitLab has released a fix for a newly discovered security flaw, and is urging its users to install immediately as it addresses a high-severity vulnerability that can cause all sorts of trouble. In a security bulletin, GitLab said an attacker could abuse scan execution policies to run pipelines (a series…
Recent Posts
- 30% Off Canon Promo Codes | June 2026
- Steam Machine and Steam Frame are coming ‘this summer’
- Valve says it’s ready to launch the Steam Machine this summer
- Best Buy slashes up to $400 off Apple tech in a limited-time sale — get AirPods, MacBooks, iPads and Apple Watches from $99.99
- The Instagram Plus subscription has officially launched
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023