• XSS.stack #1 – первый литературный журнал от юзеров форума

Web Gitlab 14.9 - Authentication Bypass Vulnerability

DarckSol

(L1) cache
Пользователь
Регистрация
17.03.2008
Сообщения
894
Реакции
182
Код:
# Exploit Title: Gitlab 14.9 - Authentication Bypass
# Exploit Authors: Greenwolf & stacksmashing
# Vendor Homepage: https://about.gitlab.com/
# Software Link: https://about.gitlab.com/install
# Version: GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2
# Tested on: Linux
# CVE : CVE-2022-1162
# References: https://github.com/Greenwolf/CVE-2022-1162
 
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts.
 
Exploit:
 
New Gitlab Accounts (created since the first affect version and if Gitlab is before the patched version) can be logged into with the following password:
 
123qweQWE!@#000000000
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх