ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ GitLab ื•ื•ืึธืก ืœืึธื–ืŸ ื—ืฉื‘ื•ืŸ ื›ื™ื™ื“ื–ืฉืึทืงื™ื ื’ ืื•ืŸ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ืงืึทืžืึทื ื“ื– ืื•ื ื˜ืขืจ ืืŸ ืื ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ

ืงืขืจืขืงื˜ื™ื•ื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืฆื• ื“ืขืจ ืคึผืœืึทื˜ืคืึธืจืžืข ืคึฟืึทืจ ืึธืจื’ืึทื ื™ื™ื–ื™ื ื’ ืงืึทืœืึทื‘ืขืจื™ื™ื˜ื™ื•ื• ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ื–ืขื ืขืŸ ืืจื•ื™ืก - GitLab 16.7.2, 16.6.4 ืื•ืŸ 16.5.6, ื•ื•ืึธืก ืคืึทืจืจื™ื›ื˜ืŸ ืฆื•ื•ื™ื™ ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–. ื“ืขืจ ืขืจืฉื˜ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2023-7028), ื•ื•ืึธืก ืื™ื– ืึทืกื™ื™ื ื“ ื“ื™ ืžืึทืงืกื™ืžื•ื ืฉื˜ืจืขื ื’ืงื™ื™ึทื˜ ืžื“ืจื’ื” (10 ืคื•ืŸ 10), ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืึธื ื›ืึทืคึผืŸ ืขืžืขืฆืขืจ ืึทื ื“ืขืจืฉ ืก ื—ืฉื‘ื•ืŸ ื“ื•ืจืš ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ืคืืจื’ืขืกืŸ ืคึผืึทืจืึธืœ ืึธืคึผื–ื•ืš ืคืึธืจืขื. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ืฉื™ืงืŸ ืึทืŸ E- ื‘ืจื™ื•ื• ืžื™ื˜ ืึท ืคึผืึทืจืึธืœ ื‘ืึทืฉื˜ืขื˜ื™ืง ืงืึธื“ ืฆื• ืึทื ื•ื•ืขืจืึทืคื™ื™ื“ E- ื‘ืจื™ื•ื• ืึทื“ืจืขืกืขืก. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืืจื•ื™ืก ื–ื™ื ื˜ ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ GitLab 16.1.0, ื•ื•ืึธืก ื™ื ื˜ืจืึธื•ื“ื•ืกื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉื™ืงืŸ ืึท ืคึผืึทืจืึธืœ ืึธืคึผื–ื•ืš ืงืึธื“ ืฆื• ืึทืŸ ืึทื ื•ื•ืขืจืึทืคื™ื™ื“ ื‘ืึทืงืึทืคึผ E- ื‘ืจื™ื•ื• ืึทื“ืจืขืก.

ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ Facts ืคื•ืŸ ืงืึทืžืคึผืจืึทืžื™ื™ื– ืคื•ืŸ ืกื™ืกื˜ืขืžืขืŸ, ืขืก ืื™ื– ืคืืจื’ืขืœื™ื™ื’ื˜ ืฆื• ืึธืคึผืฉืึทืฆืŸ ืื™ืŸ ื“ื™ gitlab-rails/production_json.log ืงืœืึธืฅ ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ื”ื˜ื˜ืคึผ ืจื™ืงื•ื•ืขืก ืฆื• ื“ื™ / ื™ื•ื–ืขืจื– / ืคึผืึทืจืึธืœ ื”ืึทื ื“ืœืขืจ ื•ื•ืึธืก ื™ื ื“ื™ืงื™ื™ืฅ ืึท ืžืขื ื’ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ืขื˜ืœืขื›ืข ื™ืžื™ื™ืœื– ืื™ืŸ ื“ื™ "params.value.email " ืคึผืึทืจืึทืžืขื˜ืขืจ. ืขืก ืื™ื– ืื•ื™ืš ืกืึทื’ื“ื–ืฉืขืกื˜ื™ื“ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืคึฟืึทืจ ืื™ื™ื ืกืŸ ืื™ืŸ ื“ื™ gitlab-rails/audit_json.log ืงืœืึธืฅ ืžื™ื˜ ื“ื™ ื•ื•ืขืจื˜ PasswordsController#create ืื™ืŸ meta.caller.id ืื•ืŸ ื™ื ื“ืึทืงื™ื™ื˜ื™ื ื’ ืึท ืžืขื ื’ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ืขื˜ืœืขื›ืข ืึทื“ืจืขืกืขืก ืื™ืŸ ื“ื™ target_details ื‘ืœืึธืง. ื“ื™ ื‘ืึทืคืึทืœืŸ ืงืขื ืขืŸ ื ื™ื˜ ื–ื™ื™ืŸ ื’ืขืขื ื“ื™ืงื˜ ืื•ื™ื‘ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ื™ื ื™ื™ื‘ืึทืœื– ืฆื•ื•ื™ื™-ืคืึทืงื˜ืึธืจ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ.

ื“ื™ ืฆื•ื•ื™ื™ื˜ืข ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, CVE-2023-5356, ืื™ื– ืคืึธืจืฉื˜ืขืœืŸ ืื™ืŸ ื“ื™ ืงืึธื“ ืคึฟืึทืจ ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ืžื™ื˜ ื“ื™ ืกืœืึทืงืง ืื•ืŸ ืžืึทื˜ื˜ืขืจืžืึธืกื˜ ื‘ืึทื“ื™ื ื•ื ื’ืก, ืื•ืŸ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื•ื™ืกืคื™ืจืŸ /-ืงืึทืžืึทื ื“ื– ืื•ื ื˜ืขืจ ืืŸ ืื ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืจืขื›ื˜ ืฆื• ื“ืขืจ ืคืขืœืŸ ืคื•ืŸ ื’ืขื”ืขืจื™ืง ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ื˜ืฉืขืง. ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืื™ื– ืึทืกื™ื™ื ื“ ืึท ืฉื˜ืจืขื ื’ืงื™ื™ึทื˜ ืžื“ืจื’ื” ืคื•ืŸ 9.6 ืคื•ืŸ 10. ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืขืก ืื•ื™ืš ืขืœื™ืžื™ื ื™ืจืŸ ืึท ื•ื•ื™ื™ื ื™ืงืขืจ ื’ืขืคืขืจืœืขืš (7.6 ืคื•ืŸ 10) ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2023-4812), ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื‘ื™ื™ืคึผืึทืก ื“ื™ ื”ืึทืกืงืึธืžืข ืคื•ืŸ โ€‹โ€‹CODEOWNERS ื“ื•ืจืš ืึทื“ื™ื ื’ ืขื ื“ืขืจื•ื ื’ืขืŸ ืฆื• ืึท ืคืจื™ืขืจ ื‘ืื•ื•ื™ืœื™ืงื˜ ืฆื•ื ื•ื™ืคื’ื™ืกืŸ ื‘ืขื˜ืŸ.

ื“ื™ื˜ื™ื™ืœื“ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ื– ืคึผืœืึทื ื ืขื“ ืฆื• ื–ื™ื™ืŸ ื“ื™ืกืงืœืึธื•ื–ื“ 30 ื˜ืขื’ ื ืึธืš ื“ื™ ื•ื™ืกื’ืึทื‘ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืคืึทืจืจื™ื›ื˜ืŸ. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื“ืขืจืœืื ื’ื˜ ืฆื• GitLab ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ HackerOne ืก ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื‘ืจื™ื™ื˜ื”ืึทืจืฆื™ืงื™ื™ื˜ ืคึผืจืึธื’ืจืึทื.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’