Urgent: GitLab Releases Patch for Critical Vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-5356 | Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions s Incorrect authorization checks in GitLab CE/EE from all versions starting from 8.13 before 16.5.6, all versions starting from 16.6 before 16.6.4, all versions starting from 16.7 before 16.7.2, allows a user to abuse slack/mattermost integrations to execute slash commands as another user. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2023-7028 | Unauthenticated Account Takeover via Password Reset Flaw in GitLab CE/EE GitLab Community and Enterprise Editions contain a critical improper access control flaw (CWE-640) in which password reset emails for a user account could be delivered to an unverified email address. Because the password reset flow is reachable over the network without authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker could trigger a password reset for a victim's account such that the reset link lands on an attacker-controlled, unverified email address, then set a new password and hijack the account. Taking over an account gives the attacker that account's privileges, so compromise of an administrator account could expose the instance's code repositories, settings, and any secrets or CI/CD credentials they can reach. All GitLab CE/EE versions from 16.1 through 16.7 prior to the patched releases (16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4, and 16.7.2) are affected. The flaw is under active exploitation: it carries an EPSS of 94.6% (100th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2024-05-01, and news coverage confirms attackers are hijacking accounts in the wild. Do: Upgrade affected GitLab CE/EE instances immediately to the patched release for your track — 16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4, or 16.7.2 (or later) — prioritizing internet-facing instances given active exploitation and the KEV listing. Audit user accounts for unverified or unexpected email addresses and review logs for password reset activity to identify possible takeovers, and rotate credentials for any high-privilege accounts you suspect were compromised. | 9.8 | 95% | KEV PoC ×2 |
| largetens of thousands of internet-exposed GitLab instances (public internet-wide scan data) |
Full article308 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJan 12, 2024DevSecOps / Software security
GitLab has released security updates to address two critical vulnerabilities, including one that could be exploited to take over accounts without requiring any user interaction.
Tracked as CVE-2023-7028, the flaw has been awarded the maximum severity of 10.0 on the CVSS scoring system and could facilitate account takeover by sending password reset emails to an unverified email address.
The DevSecOps platform said the vulnerability is the result of a bug in the email verification process, which allowed users to reset their password through a secondary email address.
It affects all self-managed instances of GitLab Community Edition (CE) and Enterprise Edition (EE) using the below versions -
- 16.1 prior to 16.1.6
- 16.2 prior to 16.2.9
- 16.3 prior to 16.3.7
- 16.4 prior to 16.4.5
- 16.5 prior to 16.5.6
- 16.6 prior to 16.6.4
- 16.7 prior to 16.7.2
GitLab said it addressed the issue in GitLab versions 16.5.6, 16.6.4, and 16.7.2, in addition to backporting the fix to versions 16.1.6, 16.2.9, 16.3.7, and 16.4.5. The company further noted the bug was introduced in 16.1.0 on May 1, 2023.
“Within these versions, all authentication mechanisms are impacted,” GitLab said. “Additionally, users who have two-factor authentication enabled are vulnerable to password reset but not account takeover as their second authentication factor is required to login.”
Also patched by GitLab as part of the latest update is another critical flaw (CVE-2023-5356, CVSS score: 9.6), which permits a user to abuse Slack/Mattermost integrations to execute slash commands as another user.
To mitigate any potential threats, it’s advised to upgrade the instances to a patched version as soon as possible and enable 2FA, if not already, particularly for users with elevated privileges.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/01/urgent-gitlab-releases-patch-for.html