#VU65885 Improper Authentication in Gitlab Community Edition and GitLab Enterprise Edition


Published: 2022-07-29

Vulnerability identifier: #VU65885

Vulnerability risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-2303

CWE-ID: CWE-287

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Gitlab Community Edition
Universal components / Libraries / Software for developers
GitLab Enterprise Edition
Universal components / Libraries / Software for developers

Vendor: GitLab, Inc

Description

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote user can bypass 2FA enforcement enabled at the group level by using Resource Owner Password Credentials grant to obtain an access token without using 2FA.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Gitlab Community Edition: 0.1.5 - 15.2.0

GitLab Enterprise Edition: 6.2.0 - 15.2.0


External links
http://about.gitlab.com/releases/2022/07/28/security-release-gitlab-15-2-1-released/


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability