The corrective updates for the collaborative development platform GitLab versions 14.8.2, 14.7.4, and 14.6.5 address a critical vulnerability (CVE-2022-0735) that allows unauthorized users to extract registration tokens in GitLab Runner, which is used to invoke handlers during the project code build process in continuous integration systems. Details are not currently provided, only that the issue is caused by information leakage when using Quick Actions commands.
The issue was identified by GitLab staff and affects versions from 12.10 to 14.6.5, from 14.7 to 14.7.4, and from 14.8 to 14.8.2. Users maintaining their own GitLab installations are advised to apply the update or patch as soon as possible. The issue has been resolved by restricting access to Quick Actions commands only to users with write permissions. After updating or applying the separate 'token-prefix' patches, previously created registration tokens in the Runner for groups and projects will be reset and regenerated.
In addition to the critical vulnerability, the new versions also fix 6 less severe vulnerabilities that could allow unprivileged users to add other users to groups, mislead users through content manipulation of Snippets, leak environment variables via the sendmail delivery method, determine user presence through the GraphQL API, leak passwords when mirroring repositories over SSH in pull mode, and execute DoS attacks via the comment submission system.
Source: opennet.ru
