CVE-2016-4340
HIGHGitLab 8.2.0-8.6.7 Authenticated Privilege Escalation via Impersonate
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-4340. PoCs published by Kaimi.
AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in GitLab where any registered user can impersonate another user, including administrators, by crafting a specific POST request with a valid authenticity token. The vulnerability affects multiple versions of GitLab from 8.2.0 to 8.7.0.
Description
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.
Exploits (1)
This exploit demonstrates a privilege escalation vulnerability in GitLab where any registered user can impersonate another user, including administrators, by crafting a specific POST request with a valid authenticity token. The vulnerability affects multiple versions of GitLab from 8.2.0 to 8.7.0.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H