GitLab has released another series of patches for its collaborative development platform – versions 15.3.2, 15.2.4, and 15.1.6 – that address a critical vulnerability (CVE-2022-2992) allowing an authenticated user to execute code remotely on the server. Similar to the vulnerability CVE-2022-2884, fixed last week, the new issue exists in the API for importing data from GitHub. This vulnerability is also present in the releases 15.3.1, 15.2.3, and 15.1.5, where the first issue in the GitHub import code was addressed.
Details of the exploitation are not yet provided. Information about the vulnerability was sent to GitLab under the active HackerOne bug bounty program, but unlike the previous issue, it was discovered by a different participant. As a workaround, administrators are advised to disable the import functionality from GitHub (in the web interface of GitLab: "Menu" -> "Admin" -> "Settings" -> "General" -> "Visibility and access controls" -> "Import sources" -> disable "GitHub").
Additionally, the proposed updates fix another 14 vulnerabilities, two of which are categorized as critical, ten assigned a medium danger rating, and two marked as low risk. The critical vulnerabilities include: CVE-2022-2865, which allows an attacker to inject their JavaScript code into pages viewed by other users through manipulation of colored labels, and CVE-2022-2527, which enables content injection via the description field in the Incidents Timeline. Medium-risk vulnerabilities are primarily related to the potential for denial of service attacks.
Source: opennet.ru
