Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| gitlab | affected | >= 15.3.0, < 16.5.6 | vendor fix → 16.5.6 | osv BIT-gitlab-2023-4812 | |
| gitlab | affected | >= 16.6.0, < 16.6.4 | vendor fix → 16.6.4 | osv BIT-gitlab-2023-4812 | |
| gitlab | affected | >= 16.7.0, < 16.7.2 | vendor fix → 16.7.2 | osv BIT-gitlab-2023-4812 | |
| https://gitlab.com/gitlab-org/gitlab | affected | >= b189ba070558de141d90142340de25bd3edcbefc, < 328c57b01842700127bb3d1302f5b5b967fa4442 | vendor fix → 328c57b01842700127bb3d1302f5b5b967fa4442 | osv | |
| https://gitlab.com/gitlab-org/gitlab | affected | >= 94991886af3e3820aa09fa353b29cf8557c93168, < 1873157df5a1e602741dc5fbe790db81888baea4 | vendor fix → 1873157df5a1e602741dc5fbe790db81888baea4 | osv | |
| https://gitlab.com/gitlab-org/gitlab | affected | >= 9e7d34f7ff11405ece06ec398b66965d153cee6f, < 847f5d82ad6aa1208a61fee603fc0e0ce1786f19 | vendor fix → 847f5d82ad6aa1208a61fee603fc0e0ce1786f19 | osv | |
| gitlab | fixed | 16.5.6 | vendor fix → 16.5.6 | osv BIT-gitlab-2023-4812 | |
| gitlab | fixed | 16.6.4 | vendor fix → 16.6.4 | osv BIT-gitlab-2023-4812 | |
| gitlab | fixed | 16.7.2 | vendor fix → 16.7.2 | osv BIT-gitlab-2023-4812 | |
| https://gitlab.com/gitlab-org/gitlab | fixed | 328c57b01842700127bb3d1302f5b5b967fa4442 | vendor fix → 328c57b01842700127bb3d1302f5b5b967fa4442 | osv | |
| https://gitlab.com/gitlab-org/gitlab | fixed | 1873157df5a1e602741dc5fbe790db81888baea4 | vendor fix → 1873157df5a1e602741dc5fbe790db81888baea4 | osv | |
| https://gitlab.com/gitlab-org/gitlab | fixed | 847f5d82ad6aa1208a61fee603fc0e0ce1786f19 | vendor fix → 847f5d82ad6aa1208a61fee603fc0e0ce1786f19 | osv | |
| GitLab/GitLab GitLab · GitLab | affected | >= 15.3, < 16.5.6 | none available | cve_cna | |
| GitLab/GitLab GitLab · GitLab | affected | >= 16.6, < 16.6.4 | none available | cve_cna | |
| GitLab/GitLab GitLab · GitLab | affected | >= 16.7, < 16.7.2 | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.