Skip to content
Rotary Mexico

Rotary Mexico

Primary Menu Rotary Mexico

Rotary Mexico

  • Home
  • Commerce sector
  • Commerce sales
  • Commerce law
  • Commerce account
  • Commerce payments
  • Commerce account

GitLab releases security patch to make account takeover easier • The Register

3 months ago Heather K. Leach

GitLab on Thursday released security updates for three versions of GitLab Community Edition (CE) and Enterprise Edition (EE) software that fixes, among other flaws, a critical hard-coded password bug.

The cloud-hosted software version control service has released versions 14.9.2, 14.8.5, and 14.7.7 of its self-hosted CE and EE software, patching a “critical” security vulnerability (CVE-2022-1162), along with two rated “high”, nine rated “medium”, and four rated “low”.

“A hard-coded password has been set for accounts registered using a OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take control of accounts,” said society in his opinion.

It emerges from modified files the password.rb module generated a fake strong password for testing by concatenating “123qweQWE!@#” with a number of “0”s equal to the difference of User.password_length.maxuser-defined, and DEFAULT_LENGTHhardcoded with the value 12.

So if an organization has configured their own instance of GitLab to accept passwords of up to 21 characters, it looks like an account takeover attack on that GitLab installation could use the default password “123qweQWE! @#000000000” to access accounts created via OmniAuth.

The bug, with a CVSS score of 9.1, was found internally by GitLab and the fix has already been applied to the company’s hosted service, in conjunction with a limited password reset.

“We performed a GitLab.com password reset for a select set of users beginning at 3:38 PM UTC [Thursday]”, states the security advisory. “Our investigation shows no indication that users or accounts have been compromised, but we are taking precautionary measures for the security of our users.

GitLab has also released a script – with a “at your own risk” warning – to automatically reset user passwords in self-managed GitLab instances.

Other notable fixes for the advisory include a stored XSS vulnerability (CVE-2022-1175) resulting from incorrect sanitization of entries in the notes. This allowed an attacker to exploit cross-site scripting by injecting HTML.

Additionally, there is CVE-2022-1190, which allows a stored XSS attack by placing code in multi-word step references in issue descriptions, comments, etc.

These last two CVEs are both classified as high severity, with CVSS scores of 8.7. While medium and low severity bugs aren’t as much of a concern, GitLab wants everyone to update regardless.

“We strongly recommend that all GitLab installations be immediately upgraded to one of these releases,” the GitLab advisory reads.

GitLab complaints have 30 million registered users and one million active license users, with more than 100,000 organizations using the company’s software. ®

Continue Reading

Previous The Global Account Reconciliation Software Market to be Driven by Technological Advancements During the Forecast Period 2021-2026
Next Account Reconciliation Software Market Revenue, Growth Drivers, Trends, Key Companies, Forecast to 2028 – FortBendNow

More Stories

  • Commerce account

BREAKING: Judges to assess tax penalty limits for foreign accounts

21 hours ago Heather K. Leach
  • Commerce account

Highest savings account rates today: June 20, 2022

2 days ago Heather K. Leach
  • Commerce account

Spend Analysis Software Market Expected to Witness High Demand Due to Rising Number of Applications in the Market – Indian Defense News

3 days ago Heather K. Leach

Categories

  • Commerce account
  • Commerce law
  • Commerce payments
  • Commerce sales
  • Commerce sector

commerce industry commerce market commerce platforms commerce sales commerce sector covid pandemic digital commerce electronic commerce growth commerce online sales online shopping retail sales supply chain united states vice president

Recent Posts

  • Inheritance by Listco shareholders through trusts

  • Record Month for Ecommerce Sales at Golfmonthly.com Reveals Online Shopping Habits of Golfers

  • BREAKING: Judges to assess tax penalty limits for foreign accounts

  • Klein Law Firm announces June 24, 2022 deadline for lead plaintiff in class action lawsuit filed on behalf of shareholders of Innovative Industrial Properties, Inc.

  • Drought Special Edition: Updated California Environmental Laws and Policies – June 2022 | Allen Matkins

Archives

  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • November 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • September 2018
  • July 2018
  • April 2018
  • January 2018

You may have missed

  • Commerce law

Inheritance by Listco shareholders through trusts

3 hours ago Heather K. Leach
  • Commerce sales

Record Month for Ecommerce Sales at Golfmonthly.com Reveals Online Shopping Habits of Golfers

19 hours ago Heather K. Leach
  • Commerce account

BREAKING: Judges to assess tax penalty limits for foreign accounts

21 hours ago Heather K. Leach
  • Commerce law

Klein Law Firm announces June 24, 2022 deadline for lead plaintiff in class action lawsuit filed on behalf of shareholders of Innovative Industrial Properties, Inc.

1 day ago Heather K. Leach
  • Commerce law

Drought Special Edition: Updated California Environmental Laws and Policies – June 2022 | Allen Matkins

2 days ago Heather K. Leach
  • Privacy Policy
  • Terms and Conditions
Copyright © All rights reserved.