ืคื’ื™ืขื•ืช ื‘-GitLab ื”ืžืืคืฉืจืช ืœืš ืœื”ืฉืชืœื˜ ืขืœ ื—ืฉื‘ื•ื ื•ืช ื”ืžื•ืจืฉื™ื ื‘ืืžืฆืขื•ืช OAuth, LDAP ื•-SAML

ืขื“ื›ื•ื ื™ื ืžืชืงื™ื ื™ื ืœืคืœื˜ืคื•ืจืžืช ื”ืคื™ืชื•ื— ื”ืฉื™ืชื•ืคื™ GitLab 14.7.7, 14.8.5 ื•-14.9.2 ืžื‘ื˜ืœื™ื ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2022-1162) ื”ืงืฉื•ืจื” ืœื”ื’ื“ืจืช ืกื™ืกืžืื•ืช ืžืงื•ื“ื“ื•ืช ืงืฉื™ื—ื•ืช ืขื‘ื•ืจ ื—ืฉื‘ื•ื ื•ืช ื”ืจืฉื•ืžื™ื ื‘ืืžืฆืขื•ืช ืกืคืง OmniAuth (OAuth), LDAP ื•-SAML) . ื”ืคื’ื™ืขื•ืช ืขืฉื•ื™ื” ืœืืคืฉืจ ืœืชื•ืงืฃ ืœืงื‘ืœ ื’ื™ืฉื” ืœื—ืฉื‘ื•ืŸ. ืžื•ืžืœืฅ ืœื›ืœ ื”ืžืฉืชืžืฉื™ื ืœื”ืชืงื™ืŸ ืืช ื”ืขื“ื›ื•ืŸ ื‘ืื•ืคืŸ ืžื™ื™ื“ื™. ืคืจื˜ื™ ื”ื‘ืขื™ื” ื˜ืจื ื ื—ืฉืคื•. ืžืฉืชืžืฉื™ื ืฉื—ืฉื‘ื•ื ื•ืชื™ื”ื ื”ื•ืฉืคืขื• ืžื”ื‘ืขื™ื” ื”ืชื‘ืงืฉื• ืœืืคืก ืืช ื”ืกื™ืกืžืื•ืช ืฉืœื”ื. ื”ื‘ืขื™ื” ื–ื•ื”ืชื” ืขืœ ื™ื“ื™ ืขื•ื‘ื“ื™ GitLab ื•ื”ื—ืงื™ืจื” ืœื ื”ืขืœืชื” ืขืงื‘ื•ืช ืฉืœ ืคืฉืจื” ืฉืœ ืžืฉืชืžืฉื™ื.

ื”ื’ืจืกืื•ืช ื”ื—ื“ืฉื•ืช ื’ื ืžื‘ื˜ืœื•ืช 16 ืคื’ื™ืขื•ื™ื•ืช ื ื•ืกืคื•ืช, ืžืชื•ื›ืŸ 2 ืžืกื•ืžื ื•ืช ื›ืžืกื•ื›ื ื•ืช, 9 ื‘ื™ื ื•ื ื™ื•ืช ื•-5 ืื™ื ืŸ ืžืกื•ื›ื ื•ืช. ื‘ืขื™ื•ืช ืžืกื•ื›ื ื•ืช ื›ื•ืœืœื•ืช ืืคืฉืจื•ืช ืฉืœ ื”ื–ืจืงืช HTML (XSS) ื‘ื”ืขืจื•ืช (CVE-2022-1175) ื•ื”ืขืจื•ืช/ืชื™ืื•ืจื™ื ื‘ืกื•ื’ื™ื” (CVE-2022-1190).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”