CVE-2016-4340: GitLab

High severity, CVSS 8.8. EPSS: 10.1% chance of exploitation in the next 30 days.

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

Affected products

  • GitLab GitLab: version 8.2.0 only; version 8.2.1 only; version 8.2.2 only; version 8.2.3 only; version 8.2.4 only; version 8.3.0 only; …

Published 2017-01-23. Last modified 2026-06-17.