Vulnerability in GitLab allowing the takeover of accounts that are authenticated via OAuth, LDAP, and SAML.

In the corrective updates for the collaborative development platform GitLab 14.7.7, 14.8.5, and 14.9.2, a critical vulnerability (CVE-2022-1162) has been fixed related to the installation of hardcoded passwords for accounts registered using the OmniAuth provider (OAuth, LDAP, and SAML). This vulnerability potentially allows an attacker to gain access to the account. All users are strongly advised to urgently install the update. Details of the issue are currently not disclosed. For users whose accounts were affected by the issue, a password reset has been initiated. The problem was identified by GitLab employees, and the investigation found no evidence of user compromise.

The new versions also fix 16 other vulnerabilities, of which 2 are classified as critical, 9 as moderate, and 5 as low risk. Among the critical issues are the ability to inject HTML code (XSS) in notes (CVE-2022-1175) and comments/descriptions in issues (CVE-2022-1190).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster