Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| gitlab | affected | >= 16.1.0, < 16.1.6 | vendor fix → 16.1.6 | osv BIT-gitlab-2023-7028 | |
| gitlab | affected | >= 16.2.0, < 16.2.9 | vendor fix → 16.2.9 | osv BIT-gitlab-2023-7028 | |
| gitlab | affected | >= 16.3.0, < 16.3.7 | vendor fix → 16.3.7 | osv BIT-gitlab-2023-7028 | |
| gitlab | affected | >= 16.4.0, < 16.4.5 | vendor fix → 16.4.5 | osv BIT-gitlab-2023-7028 | |
| gitlab | affected | >= 16.5.0, < 16.5.6 | vendor fix → 16.5.6 | osv BIT-gitlab-2023-7028 | |
| gitlab | affected | >= 16.6.0, < 16.6.4 | vendor fix → 16.6.4 | osv BIT-gitlab-2023-7028 | |
| gitlab | affected | >= 16.7.0, < 16.7.2 | vendor fix → 16.7.2 | osv BIT-gitlab-2023-7028 | |
| https://gitlab.com/gitlab-org/gitlab | affected | >= 4961ad113f3afe23965ac12285eaab31315ab0c6, < 39f92f67961c5a8b85b738628916fe814e1b53c2 | vendor fix → 39f92f67961c5a8b85b738628916fe814e1b53c2 | osv | |
| https://gitlab.com/gitlab-org/gitlab | affected | >= 3adc0fe6e7c163bedd7faa5f0c4d1e5fbb6bf3c5, < 0dc0c45e5c515fcb6aa87a280a50140e1715bcd8 | vendor fix → 0dc0c45e5c515fcb6aa87a280a50140e1715bcd8 | osv | |
| https://gitlab.com/gitlab-org/gitlab | affected | >= 3dfd4e0bcc7eae4330e7fed87ec74bee9a8bdf2d, < 4b39d8fe4183ca86b4b425ffc5e1f9f0a4d2d222 | vendor fix → 4b39d8fe4183ca86b4b425ffc5e1f9f0a4d2d222 | osv | |
| https://gitlab.com/gitlab-org/gitlab | affected | >= e4c1c182610739c1b1d10a8eacbea1f5aa837ad6, < 847c8151481a0f1bbdfd008ff932a5c5740b47a1 | vendor fix → 847c8151481a0f1bbdfd008ff932a5c5740b47a1 | osv | |
| https://gitlab.com/gitlab-org/gitlab | affected | >= fc87c9d4cca1536abcf902b4128f5c2004d87162, < 328c57b01842700127bb3d1302f5b5b967fa4442 | vendor fix → 328c57b01842700127bb3d1302f5b5b967fa4442 | osv | |
| https://gitlab.com/gitlab-org/gitlab | affected | >= 94991886af3e3820aa09fa353b29cf8557c93168, < 1873157df5a1e602741dc5fbe790db81888baea4 | vendor fix → 1873157df5a1e602741dc5fbe790db81888baea4 | osv | |
| https://gitlab.com/gitlab-org/gitlab | affected | >= 9e7d34f7ff11405ece06ec398b66965d153cee6f, < 847f5d82ad6aa1208a61fee603fc0e0ce1786f19 | vendor fix → 847f5d82ad6aa1208a61fee603fc0e0ce1786f19 | osv | |
| gitlab | fixed | 16.1.6 | vendor fix → 16.1.6 | osv BIT-gitlab-2023-7028 | |
| gitlab | fixed | 16.2.9 | vendor fix → 16.2.9 | osv BIT-gitlab-2023-7028 | |
| gitlab | fixed | 16.3.7 | vendor fix → 16.3.7 | osv BIT-gitlab-2023-7028 | |
| gitlab | fixed | 16.4.5 | vendor fix → 16.4.5 | osv BIT-gitlab-2023-7028 | |
| gitlab | fixed | 16.5.6 | vendor fix → 16.5.6 | osv BIT-gitlab-2023-7028 | |
| gitlab | fixed | 16.6.4 | vendor fix → 16.6.4 | osv BIT-gitlab-2023-7028 | |
| gitlab | fixed | 16.7.2 | vendor fix → 16.7.2 | osv BIT-gitlab-2023-7028 | |
| https://gitlab.com/gitlab-org/gitlab | fixed | 39f92f67961c5a8b85b738628916fe814e1b53c2 | vendor fix → 39f92f67961c5a8b85b738628916fe814e1b53c2 | osv | |
| https://gitlab.com/gitlab-org/gitlab | fixed | 0dc0c45e5c515fcb6aa87a280a50140e1715bcd8 | vendor fix → 0dc0c45e5c515fcb6aa87a280a50140e1715bcd8 | osv | |
| https://gitlab.com/gitlab-org/gitlab | fixed | 4b39d8fe4183ca86b4b425ffc5e1f9f0a4d2d222 | vendor fix → 4b39d8fe4183ca86b4b425ffc5e1f9f0a4d2d222 | osv | |
| https://gitlab.com/gitlab-org/gitlab | fixed | 847c8151481a0f1bbdfd008ff932a5c5740b47a1 | vendor fix → 847c8151481a0f1bbdfd008ff932a5c5740b47a1 | osv | |
| https://gitlab.com/gitlab-org/gitlab | fixed | 328c57b01842700127bb3d1302f5b5b967fa4442 | vendor fix → 328c57b01842700127bb3d1302f5b5b967fa4442 | osv | |
| https://gitlab.com/gitlab-org/gitlab | fixed | 1873157df5a1e602741dc5fbe790db81888baea4 | vendor fix → 1873157df5a1e602741dc5fbe790db81888baea4 | osv | |
| https://gitlab.com/gitlab-org/gitlab | fixed | 847f5d82ad6aa1208a61fee603fc0e0ce1786f19 | vendor fix → 847f5d82ad6aa1208a61fee603fc0e0ce1786f19 | osv | |
| GitLab/GitLab GitLab · GitLab | affected | >= 16.1, < 16.1.6 | none available | cve_cna | |
| GitLab/GitLab GitLab · GitLab | affected | >= 16.2, < 16.2.9 | none available | cve_cna | |
| GitLab/GitLab GitLab · GitLab | affected | >= 16.3, < 16.3.7 | none available | cve_cna | |
| GitLab/GitLab GitLab · GitLab | affected | >= 16.4, < 16.4.5 | none available | cve_cna | |
| GitLab/GitLab GitLab · GitLab | affected | >= 16.5, < 16.5.6 | none available | cve_cna | |
| GitLab/GitLab GitLab · GitLab | affected | >= 16.6, < 16.6.4 | none available | cve_cna | |
| GitLab/GitLab GitLab · GitLab | affected | >= 16.7, < 16.7.2 | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.