2022-09-12 18:56:17 +00:00
id : CVE-2022-1162
info :
2023-04-06 21:37:02 +00:00
name : GitLab CE/EE - Hard-Coded Credentials
2022-09-12 18:56:17 +00:00
author : GitLab Red Team
severity : critical
2023-04-06 21:37:02 +00:00
description : GitLab CE/EE contains a hard-coded credentials vulnerability. A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML), allowing attackers to potentially take over accounts. This template attempts to passively identify vulnerable versions of GitLab without the need for an exploit by matching unique hashes for the application-<hash>.css file in the header for unauthenticated requests. Positive matches do not guarantee exploitability. Affected versions are 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2.
2023-09-06 11:59:08 +00:00
remediation : Tooling to find relevant hashes based on the semantic version ranges specified in the CVE is linked in the reference section below.
2022-09-12 18:56:17 +00:00
reference :
- https://gitlab.com/gitlab-com/gl-security/threatmanagement/redteam/redteam-public/cve-hash-harvester
- https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1162.json
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-1162
2023-04-12 10:55:48 +00:00
- http://packetstormsecurity.com/files/166828/Gitlab-14.9-Authentication-Bypass.html
2023-04-06 21:37:02 +00:00
- https://nvd.nist.gov/vuln/detail/cve-2022-1162
2022-09-12 18:56:17 +00:00
classification :
2022-09-14 19:35:00 +00:00
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cvss-score : 9.8
2022-09-12 18:56:17 +00:00
cve-id : CVE-2022-1162
2022-09-14 19:35:00 +00:00
cwe-id : CWE-798
2023-10-26 18:00:24 +00:00
epss-score : 0.17325
2023-11-09 06:04:52 +00:00
epss-percentile : 0.95562
2023-09-06 11:59:08 +00:00
cpe : cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
2022-09-12 18:56:17 +00:00
metadata :
2023-04-28 08:11:21 +00:00
max-request : 1
2023-07-11 19:49:27 +00:00
vendor : gitlab
product : gitlab
2023-09-06 11:59:08 +00:00
shodan-query : http.title:"GitLab"
2023-04-12 10:55:48 +00:00
tags : cve,cve2022,gitlab,packetstorm
2022-09-12 18:56:17 +00:00
2023-04-27 04:28:59 +00:00
http :
2022-09-12 18:56:17 +00:00
- method : GET
path :
- "{{BaseURL}}/users/sign_in"
redirects : true
max-redirects : 3
matchers :
- type : word
words :
- "003236d7e2c5f1f035dc8b67026d7583ee198b568932acd8faeac18cec673dfa"
- "1d840f0c4634c8813d3056f26cbab7a685d544050360a611a9df0b42371f4d98"
- "6eb5eaa5726150b8135a4fd09118cfd6b29f128586b7fa5019a04f1c740e9193"
- "6fa9fec63ba24ec06fcae0ec30d1369619c2c3323fe9ddc4849af86457d59eef"
- "cfa6748598b5e507db0e53906a7639e2c197a53cb57da58b0a20ed087cc0b9d5"
- "f8ba2470fbf1e30f2ce64d34705b8e6615ac964ea84163c8a6adaaf8a91f9eac"
condition : or
extractors :
- type : regex
group : 1
regex :
- '(?:application-)(\S{64})(?:\.css)'
2023-11-09 10:11:53 +00:00
# digest: 490a00463044022057ab19afe2b9026be1fa0943a966be174377653141931e1c00189fa1840636d30220399f481dc082a0f62e7ad810b687a32d81d99d08dd49b06f398f3f1ea2adefcc:922c64590222798bb761d5b6d8e72950