• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
new security vulnerability affects thousands of gitlab instances

New Security Vulnerability Affects Thousands of GitLab Instances

You are here: Home / General Cyber Security News / New Security Vulnerability Affects Thousands of GitLab Instances
March 4, 2022

Scientists have disclosed aspects of a now-patched security vulnerability in GitLab, an open-supply DevOps program, that could likely enable a remote, unauthenticated attacker to get better user-linked facts.

Tracked as CVE-2021-4191 (CVSS rating: 5.3), the medium-severity flaw influences all variations of GitLab Neighborhood Version and Enterprise Version starting from 13. and all versions starting off from 14.4 and prior to 14.8.

Automatic GitHub Backups

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Credited with exploring and reporting the flaw is Jake Baines, a senior security researcher at Rapid7. Following liable disclosure on November 18, 2021, patches were being released as section of GitLab critical security releases 14.8.2, 14.7.4, and 14.6.5 delivered on February 25, 2022.

“The vulnerability is the final result of a missing authentication look at when executing specified GitLab GraphQL API queries,” Baines stated in a report revealed Thursday. “A remote, unauthenticated attacker can use this vulnerability to collect registered GitLab usernames, names, and email addresses.”

Prosperous exploitation of the API information leak could allow malicious actors to enumerate and compile lists of reputable usernames belonging to a focus on that can then be utilized as a stepping stone to perform brute-force attacks, together with password guessing, password spraying, and credential stuffing.

Prevent Data Breaches

“The info leak also likely enables an attacker to generate a new username wordlist based on GitLab installations — not just from gitlab.com but also from the other 50,000 GitLab cases that can be achieved from the internet,” Baines stated.

In addition to CVE-2021-4191, the patch also addresses six other security flaws, a person of which is a critical issue (CVE-2022-0735, CVSS rating: 9.6) that allows an unauthorized attacker to siphon the runner registration tokens utilised to authenticate and authorize CI/CD work hosted on GitLab situations.

Identified this article interesting? Follow THN on Fb, Twitter  and LinkedIn to read far more unique content material we write-up.


Some parts of this report are sourced from:
thehackernews.com

Previous Post: «russia releases list of ips, domains attacking its infrastructure with Russia Releases List of IPs, Domains Attacking Its Infrastructure with DDoS Attacks
Next Post: Russian Claims YouTube “Misinformation” to Blame for Protests Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Freejacking Campaign By PurpleUrchin Bypasses Captchas
  • ChatGPT Used to Develop New Malicious Tools
  • Dark Web Actors Fight For Drug Trafficking and Illegal Pharmacy Supremacy
  • Kinsing Cryptojacking Hits Kubernetes Clusters via Misconfigured PostgreSQL
  • New Study Uncovers Text-to-SQL Model Vulnerabilities Allowing Data Theft and DoS Attacks
  • UK insurer announces ‘world-first’ cyber catastrophe bond
  • Why Do User Permissions Matter for SaaS Security?
  • FCC plans strict overhaul of 15-year-old US data breach regulations
  • Security updates for Windows 7 finally end, users urged to upgrade
  • Global Cyber-Attack Volume Surges 38% in 2022

Copyright © TheCyberSecurity.News, All Rights Reserved.