GitLab Patched Critical Account Takeover Vulnerability

By Admin 3 Min Read 0

GitLab, a company that provides a single application for managing git repositories, has addressed a critical severity vulnerability that could allow remote attackers to take over user accounts using hardcoded passwords.

GitLab published a security advisory on Thursday, saying “A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts. This is a critical severity issue.”

The bug which can be tracked as CVE-2022-1162, is having a CVSS score of 9.1 out of 10, was discovered by GitLab internal team affects both GitLab Community Edition (CE) and Enterprise Edition (EE).

GitLab strongly recommends that all installations running an affected version should be upgraded to the latest version as soon as possible.

Gitlab says there is no indication that users or accounts have been compromised but for precautionary measures, they had reset the passwords of a limited number of GitLab.com users as part of the mitigation effort.

Along with this critical account takeover bug, GitLab has fixed below the following vulnerabilities –

Title Severity
Static passwords inadvertently set during OmniAuth-based registration critical
Stored XSS in notes high
Stored XSS on Multi-word milestone reference high
Denial of service caused by a specially crafted RDoc file medium
GitLab Pages access tokens can be reused on multiple domains medium
GitLab Pages uses default (disabled) server Timeouts and a weak TCP Keep-Alive timeout medium
Incorrect include in pipeline definition exposes masked CI variables in UI medium
Regular expression denial of service in release asset link medium
Latest Commit details from private projects leaked to guest users via Merge Requests medium
CI/CD analytics are available even when public pipelines are disabled medium
Absence of limit for the number of tags that can be added to a runner can cause performance issues medium
Client DoS through rendering crafted comments medium
Blind SSRF Through Repository Mirroring low
Bypass of branch restriction in Asana integration low
Readable approval rules by Guest user low
Redact InvalidURIError error messages low
Project import maps members’ created_by_id users based on source user ID low

“We are dedicated to ensuring all aspects of GitLab that are exposed to customers or that host customer data are held to the highest security standards. As part of maintaining good security hygiene, it is highly recommended that all customers upgrade to the latest security release for their supported version.”- GitLab added.

Advertisement

Community Discussion

Join the conversation. Ask questions, share solutions, and help others.

0 Comments

Be the first to start the discussion!

Leave a Comment

Your email address will not be published. Required fields are marked *

We respect your privacy, your information is safe with us.

Latest Articles

View all