GitLab users told to install emergency security fix immediately

Representational image depecting cybersecurity protection
(Image credit: Shutterstock)

GitLab has released a fix for a newly discovered security flaw, and is urging its users to install immediately as it addresses a high-severity vulnerability that can cause all sorts of trouble. 

In a security bulletin, GitLab said an attacker could abuse scan execution policies to run pipelines (a series of automated tasks) as another user. 

This flaw is now tracked as CVE-2023-4998 and carries a severity score of 9.6. It impacts a couple of versions of the software, namely GitLab Community Edition (CE) and Enterprise Edition (EE) versions 13.12 through 16.2.7, and versions 16.3 through 16.3.4.

According to a BleepingComputer report, a threat actor could impersonate a user without their knowledge and permission, and access sensitive information or run malicious code, modify data, or trigger specific events within the GitLab system. Given that GitLab is a code management platform, the vulnerability could lead to intellectual property theft, data leaks, supply chain attacks, and more, the publication claims.

Fixes and workarounds

According to a BleepingComputer report, a threat actor could impersonate a user without their knowledge and permission, and access sensitive information or run malicious code, modify data, or trigger specific events within the GitLab system. Given that GitLab is a code management platform, the vulnerability could lead to intellectual property theft, data leaks, supply chain attacks, and more, the publication claims.

"We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possible,” GitLab said in the advisory. 

The vulnerability, discovered by security researcher Johan Carlsson, actually stems from a previous flaw that apparently wasn’t properly addressed. Last month, a vulnerability tracked as VE-2023-3932 was found and patched. Back then, it was a medium-severity flaw. However, Carlsson found a way to work around the fix, and even discovered that the new flaw carries even more weight (hence the new severity score of 9.6).

Users who run GitLab versions older than 16.2 should make sure they don’t have “Direct transfers” and “Security policies” both turned on, as that will make the endpoint vulnerable. Users should have just one turned at any point in time, the advisory said. 

GitLab can be updated via GitLab Runner packages from the official website.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Shadowed hands on a digital background reaching for a login prompt.
This worrying Git flaw could lead to users leaking credentials
A person's fingers type at a keyboard, with a digital security screen with a lock on it overlaid.
Veeam backup software has a serious security flaw - here's how to stay safe
Best free Linux firewalls
SonicWall tells admins to patch worrying SSLVPN flaw immediately
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Cisco patches critical security issues, so update now
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
A young woman is working on a laptop in a relaxed office space.
I’ll admit, Microsoft’s new Windows 11 update surprised me with its usefulness, providing accessibility fixes, a gamepad keyboard layout, and PC spec cards
inZOI promotional material.
inZOI has become the most wishlisted game on Steam, but I wouldn't get too caught up in the hype
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Nespresso Vertuo Pop machine in Candy Pink with coffee drinks and capsules
My favorite Nespresso coffee maker just got a fresh new makeover, and now I love it even more
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC