CVE-2022-1162: GitLab CE/EE – Hard-Coded Credentials

CVE-2022-1162: GitLab CE/EE - Hard-Coded Credentials-渗透云记 - 专注于网络安全与技术分享
CVE-2022-1162: GitLab CE/EE – Hard-Coded Credentials
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-1162: Gitlab CE/EE – Hard-Coded Credentials

漏洞描述

GitLab CE/EE contains a hard-coded credentials vulnerability. A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML), allowing attackers to potentially take over accounts. This template attempts to passively identify vulnerable versions of GitLab without the need for an exploit by matching unique hashes for the application-<hash>.css file in the header for unauthenticated requests. Positive matches do not guarantee exploitability. Affected versions are 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享