PT-2022-2799 · Gitlab · Gitlab Ce/Ee+1

Nick Malcolm

·

Published

2022-06-03

·

Updated

2024-03-06

·

CVE-2022-1680

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab Enterprise Edition versions 11.10 through 14.9.5 GitLab Enterprise Edition versions 14.10 through 14.10.4 GitLab Enterprise Edition versions 15.0 through 15.0.1
Description The issue is related to the SCIM feature in GitLab, which can allow an attacker to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker-controlled email address, thus taking over those accounts in the absence of 2FA. The attacker can also change the display name and username of the targeted account. This issue affects GitLab Enterprise Edition when group SAML SSO is configured.
Recommendations For GitLab Enterprise Edition versions 11.10 through 14.9.5, update to version 14.9.5 or later. For GitLab Enterprise Edition versions 14.10 through 14.10.4, update to version 14.10.4 or later. For GitLab Enterprise Edition versions 15.0 through 15.0.1, update to version 15.0.1 or later. As a temporary workaround, consider disabling the SCIM feature until a patch is available. Restrict access to the SCIM feature to minimize the risk of exploitation. Enable 2FA to prevent account takeover.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2022-03328
BIT-GITLAB-2022-1680
CVE-2022-1680

Affected Products

Gitlab
Gitlab Ce/Ee