PT-2024-1045 · Gitlab · Gitlab
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 16.1 through 16.1.5
GitLab CE/EE versions 16.2 through 16.2.8
GitLab CE/EE versions 16.3 through 16.3.6
GitLab CE/EE versions 16.4 through 16.4.4
GitLab CE/EE versions 16.5 through 16.5.5
GitLab CE/EE versions 16.6 through 16.6.3
GitLab CE/EE versions 16.7 through 16.7.1
Description
An improper access control issue exists in the password recovery process that allows password reset emails to be sent to unverified email addresses. A remote attacker can exploit this by manipulating the forgotten password recovery form, potentially leading to full account takeover of an arbitrary user. This exploitation is possible if the target account does not have two-factor authentication enabled or if the attacker bypasses it. Approximately 5,379 instances worldwide were identified as vulnerable. The attack involves the use of the
user[email][] parameter to direct the reset code to an attacker-controlled address.Recommendations
Update GitLab CE/EE 16.1 to version 16.1.6
Update GitLab CE/EE 16.2 to version 16.2.9
Update GitLab CE/EE 16.3 to version 16.3.7
Update GitLab CE/EE 16.4 to version 16.4.5
Update GitLab CE/EE 16.5 to version 16.5.6
Update GitLab CE/EE 16.6 to version 16.6.4
Update GitLab CE/EE 16.7 to version 16.7.2
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab