GitLab released security updates for Community Edition and Enterprise Edition to fix multiple vulnerabilities in versions 16.2.2, 16.1.3, and 16.0.8, and urged self-managed customers to upgrade immediately. The fixes addressed two high-severity Regular Expression Denial of Service (ReDoS) flaws in Markdown processing, along with several medium- and low-severity issues involving cross-site scripting, denial of service, token exposure, authorization weaknesses, and information disclosure. GitLab.com was already running the patched version when the notice was issued, and the release also updated bundled Mattermost to 7.10.4 and Redis to 6.2.13 to mitigate additional security issues.
One of the patched flaws, tracked as CVE-2023-3932, affected GitLab Enterprise Edition and could allow an attacker to run pipeline jobs as an arbitrary user through scheduled security scan policies because of incorrect user management. The issue affected GitLab EE versions from 13.12 before 16.0.8, from 16.1.0 before 16.1.3, and from 16.2.0 before 16.2.2; it was later assigned a CVSS v3.1 score of 5.3 and credited to a HackerOne report submitted by researcher vaib25vicky.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2023-3932 states that the vulnerability was published on August 3, 2023. The issue affects GitLab EE and could allow pipeline jobs to run as an arbitrary user through scheduled security scan policies.
On August 1, 2023, GitLab released security updates for Community Edition and Enterprise Edition and urged affected self-managed installations to upgrade immediately. The release fixed multiple vulnerabilities, including the pipeline job execution flaw later tracked as CVE-2023-3932, and updated bundled Mattermost and Redis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.