CVE-2023-6680Improper Certificate Validation in Gitlab

Severity
8.1HIGHNVD
EPSS
0.0%
top 92.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 15

Description

An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.5.4, and 16.6 prior to 16.6.2 allows an attacker to authenticate as another user given their public key if they use Smartcard authentication. Smartcard authentication is an experimental feature and has to be manually enabled by an administrator.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages4 packages

NVDgitlab/gitlab11.616.4.4+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2023-6680: An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 112023-12-15
GHSA
GHSA-wpj8-2grx-f965: An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 112023-12-15

📋Vendor Advisories

2
GitLab
CVE-2023-6680: An improper certificate validation issue in Smartcard authentication in GitLab EE affecting all versions from 11.6 prior to 16.4.4, 16.5 prior to 16.52023-12-15
Debian
CVE-2023-6680: gitlab - An improper certificate validation issue in Smartcard authentication in GitLab E...2023