CISA Warns of Active Exploitation of Severe GitLab Password Reset Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-7028 | Unauthenticated Account Takeover via Password Reset Flaw in GitLab CE/EE GitLab Community and Enterprise Editions contain a critical improper access control flaw (CWE-640) in which password reset emails for a user account could be delivered to an unverified email address. Because the password reset flow is reachable over the network without authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker could trigger a password reset for a victim's account such that the reset link lands on an attacker-controlled, unverified email address, then set a new password and hijack the account. Taking over an account gives the attacker that account's privileges, so compromise of an administrator account could expose the instance's code repositories, settings, and any secrets or CI/CD credentials they can reach. All GitLab CE/EE versions from 16.1 through 16.7 prior to the patched releases (16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4, and 16.7.2) are affected. The flaw is under active exploitation: it carries an EPSS of 94.6% (100th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2024-05-01, and news coverage confirms attackers are hijacking accounts in the wild. Do: Upgrade affected GitLab CE/EE instances immediately to the patched release for your track — 16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4, or 16.7.2 (or later) — prioritizing internet-facing instances given active exploitation and the KEV listing. Audit user accounts for unverified or unexpected email addresses and review logs for password reset activity to identify possible takeovers, and rotate credentials for any high-privilege accounts you suspect were compromised. | 9.8 | 95% | KEV PoC ×2 |
| largetens of thousands of internet-exposed GitLab instances (public internet-wide scan data) |
Full article344 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMay 02, 2024Vulnerability / Data Breach
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw impacting GitLab to its Known Exploited Vulnerabilities (KEV) catalog, owing to active exploitation in the wild.
Tracked as CVE-2023-7028 (CVSS score: 10.0), the maximum severity vulnerability could facilitate account takeover by sending password reset emails to an unverified email address.
GitLab, which disclosed details of the shortcoming earlier this January, said it was introduced as part of a code change in version 16.1.0 on May 1, 2023.
"Within these versions, all authentication mechanisms are impacted," the company noted at the time. "Additionally, users who have two-factor authentication enabled are vulnerable to password reset but not account takeover as their second authentication factor is required to login."
Successful exploitation of the issue can have serious consequences as it not only enables an adversary to take control of a GitLab user account, but also steal sensitive information, credentials, and even poison source code repositories with malicious code, leading to supply chain attacks.
"For instance, an attacker gaining access to the CI/CD pipeline configuration could embed malicious code designed to exfiltrate sensitive data, such as Personally Identifiable Information (PII) or authentication tokens, redirecting them to an adversary-controlled server," cloud security firm Mitiga said in a recent report.
"Similarly, tampering with repository code might involve inserting malware that compromises system integrity or introduces backdoors for unauthorized access. Malicious code or abuse of the pipeline could lead to data theft, code disruption, unauthorized access, and supply chain attacks."
The flaw has been addressed in GitLab versions 16.5.6, 16.6.4, and 16.7.2, with the patches also backported to versions 16.1.6, 16.2.9, 16.3.7, and 16.4.5.
CISA has yet to provide any other details as to how the vulnerability is being exploited in real-world attacks. In light of active abuse, federal agencies are required to apply the latest fixes by May 22, 2024, to secure their networks.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/05/cisa-warns-of-active-exploitation-of.html