Improper access control in GitLab Enterprise Edition - CVE-2022-1680

 

Improper access control in GitLab Enterprise Edition - CVE-2022-1680

Published: June 2, 2022


Vulnerability identifier: #VU63924
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-1680
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to an account takeover issue via the SCIM feature. A remote user can invite arbitrary users through their username and email, take over those accounts and change their display name and username.


Affected software

GitLab Enterprise Edition

How to mitigate CVE-2022-1680

Install updates from vendor's website.

GitLab Enterprise Edition - addressed in versions 14.9.5, 14.10.4, 15.0.1

External References

Related Security Bulletins