ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘-GitLab ื”ืžืืคืฉืจื•ืช ื—ื˜ื™ืคืช ื—ืฉื‘ื•ืŸ ื•ื‘ื™ืฆื•ืข ืคืงื•ื“ื•ืช ืชื—ืช ืžืฉืชืžืฉ ืื—ืจ

ืคื•ืจืกืžื• ืขื“ื›ื•ื ื™ื ืžืชืงื ื™ื ืœืคืœื˜ืคื•ืจืžื” ืœืืจื’ื•ืŸ ืคื™ืชื•ื— ืฉื™ืชื•ืคื™ - GitLab 16.7.2, 16.6.4 ื•-16.5.6, ื”ืžืชืงื ื™ื ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ืงืจื™ื˜ื™ื•ืช. ื”ืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื” (CVE-2023-7028), ืœื” ืžื•ืงืฆื™ืช ืจืžืช ื”ื—ื•ืžืจื” ื”ืžืจื‘ื™ืช (10 ืžืชื•ืš 10), ืžืืคืฉืจืช ืœืš ืœืชืคื•ืก ื—ืฉื‘ื•ืŸ ืฉืœ ืžื™ืฉื”ื• ืื—ืจ ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ื˜ื•ืคืก ืฉื—ื–ื•ืจ ื”ืกื™ืกืžื” ืฉื ืฉื›ื—ื”. ื”ืคื’ื™ืขื•ืช ื ื’ืจืžืช ืžื”ืืคืฉืจื•ืช ืœืฉืœื•ื— ืžื™ื™ืœ ืขื ืงื•ื“ ืื™ืคื•ืก ืกื™ืกืžื” ืœื›ืชื•ื‘ื•ืช ื“ื•ื"ืœ ืœื ืžืื•ืžืชื•ืช. ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืžืื– ื™ืฆื™ืืช GitLab 16.1.0, ืฉื”ืฆื™ื’ื” ืืช ื”ื™ื›ื•ืœืช ืœืฉืœื•ื— ืงื•ื“ ืฉื—ื–ื•ืจ ืกื™ืกืžื” ืœื›ืชื•ื‘ืช ืื™ืžื™ื™ืœ ืœื ืžืื•ืžืชืช ืœื’ื™ื‘ื•ื™.

ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื”ืขื•ื‘ื“ื•ืช ืฉืœ ืคื’ื™ืขื” ื‘ืžืขืจื›ื•ืช, ืžื•ืฆืข ืœื”ืขืจื™ืš ื‘ื™ื•ืžืŸ gitlab-rails/production_json.log ืืช ื ื•ื›ื—ื•ืชืŸ ืฉืœ ื‘ืงืฉื•ืช HTTP ืœืžื˜ืคืœ /users/password ื”ืžืฆื™ื™ืŸ ืžืขืจืš ืฉืœ ืžืกืคืจ ืžื™ื™ืœื™ื ื‘-params.value.email " ืคืจืžื˜ืจ. ื›ืžื• ื›ืŸ, ืžื•ืžืœืฅ ืœื‘ื“ื•ืง ืื ื™ืฉ ืขืจื›ื™ื ื‘ื™ื•ืžืŸ gitlab-rails/audit_json.log ืขื ื”ืขืจืš PasswordsController#create ื‘-meta.caller.id ื•ืžืฆื™ื™ืŸ ืžืขืจืš ืฉืœ ืžืกืคืจ ื›ืชื•ื‘ื•ืช ื‘ื‘ืœื•ืง target_details. ืœื ื ื™ืชืŸ ืœื”ืฉืœื™ื ืืช ื”ื”ืชืงืคื” ืื ื”ืžืฉืชืžืฉ ืžืืคืฉืจ ืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™.

ื”ืคื’ื™ืขื•ืช ื”ืฉื ื™ื™ื”, CVE-2023-5356, ืงื™ื™ืžืช ื‘ืงื•ื“ ืœืื™ื ื˜ื’ืจืฆื™ื” ืขื ืฉื™ืจื•ืชื™ Slack ื•-Mattermost, ื•ืžืืคืฉืจืช ืœืš ืœื‘ืฆืข /-ืคืงื•ื“ื•ืช ืชื—ืช ืžืฉืชืžืฉ ืื—ืจ ืขืงื‘ ื”ื™ืขื“ืจ ื‘ื“ื™ืงืช ื”ืจืฉืื•ืช ืžืชืื™ืžื”. ืœื‘ืขื™ื” ื ืงื‘ืขื” ืจืžืช ื—ื•ืžืจื” ืฉืœ 9.6 ืžืชื•ืš 10. ื”ื’ืจืกืื•ืช ื”ื—ื“ืฉื•ืช ื’ื ืžื‘ื˜ืœื•ืช ืคื’ื™ืขื•ืช ืคื—ื•ืช ืžืกื•ื›ื ืช (7.6 ืžืชื•ืš 10) (CVE-2023-4812), ื”ืžืืคืฉืจืช ืœืš ืœืขืงื•ืฃ ืืช ืื™ืฉื•ืจ CODEOWNERS ืขืœ ื™ื“ื™ ื”ื•ืกืคืช ืฉื™ื ื•ื™ื™ื ืœืคื’ื™ืขื•ืช ืฉืื•ืฉืจื• ื‘ืขื‘ืจ ื‘ืงืฉืช ืžื™ื–ื•ื’.

ืžื™ื“ืข ืžืคื•ืจื˜ ืขืœ ื ืงื•ื“ื•ืช ื”ืชื•ืจืคื” ืฉื–ื•ื”ื• ืžืชื•ื›ื ืŸ ืœื”ื™ื—ืฉืฃ 30 ื™ื•ื ืœืื—ืจ ืคืจืกื•ื ื”ืชื™ืงื•ืŸ. ื”ืคื’ื™ืขื•ื™ื•ืช ื”ื•ื’ืฉื• ืœ-GitLab ื›ื—ืœืง ืžืชื•ื›ื ื™ืช ื”ืคื’ื™ืขื•ืช ืฉืœ HackerOne.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”