Sign in
  • News
  • Interviews
  • 2021: The Comeback Year
  • Articles
  • Insights
    • Guest Post
    • Use Cases
    • Events
  • Quick Bytes
  • RESOURCES
Sign in
Welcome!Log into your account
Forgot your password?
Privacy Policy
Password recovery
Recover your password
Search
Tuesday, May 17, 2022
  • Sign in / Join
Sign in
Welcome! Log into your account
Forgot your password? Get help
Privacy Policy
Password recovery
Recover your password
A password will be e-mailed to you.
ITSECURITYWIRE FAVCON ITSECURITYWIRE FAVCON ITSecurityWire
  • News
  • Interviews
  • 2021: The Comeback Year
  • Articles
  • Insights
    • Guest Post
    • Use Cases
    • Events
  • Quick Bytes
  • RESOURCES
Home Quick Bytes GitLab Patches Critical Account Takeover Flaw
  • Quick Bytes

GitLab Patches Critical Account Takeover Flaw

By
ITsec Bureau
-
April 5, 2022
13
GitLab Patches Critical Account Takeover Flaw-01

After fixing a severe account takeover vulnerability, GitLab has reset the passwords of some user accounts.

According to the firm, when an account was registered using an OmniAuth provider in GitLab Community Edition (CE) and Enterprise Edition (EE) versions prior to 14.7.7, 14.8.5, and 14.9.2, a hardcoded password was set.

The CVE-2022-1162 (CVSS score of 9.1) critical-severity flaw could allow attackers to take control of accounts. GitLab also reset the passwords of individuals who it believes were affected by the flaw, in addition to fixing the vulnerability.

Read More: https://www.securityweek.com/gitlab-patches-critical-account-takeover-vulnerability

  • TAGS
  • Account Takeover Flaw
  • GitLab
  • GitLab Community Edition
  • OmniAuth provider
  • risk management
Previous articleTurla-Connected Infrastructure Used By New Android Spyware
Next articleLogicGate Enhances Third-Party Cyber Risk Capabilities with Black Kite Integration
ITsec Bureau
http://itsecuritywire.com/

RELATED ARTICLESMORE FROM AUTHOR

'Nerbian' novel Trojan EmploysB Advanced Anti-Detection Techniques

‘Nerbian’ novel Trojan Employs Advanced Anti-Detection Techniques

Threat Actors Spread 'Eternity' Malware-as-a-Service Using Telegram

Threat Actors Spread ‘Eternity’ Malware-as-a-Service Using Telegram

Iran-Linked OilRig APT Found Using a New Backdoor

 Iran-Linked OilRig APT Found Using a New Backdoor

Latest posts

ePlus Launches Suite of Security Services to Address Cyber Insurance Requirement Concerns

ePlus Launches Suite of Security Services to Address Cyber Insurance Requirement Concerns

October 23, 2021
Fusion Risk Management Strengthens Board of Directors with Two Key Appointments

Fusion Risk Management Strengthens Board of Directors with Two Key Appointments

June 8, 2021
Onclave Expands Executive

Onclave Expands Executive Team, Positions Company for Significant 2021 Growth

January 28, 2021
Anchore Enterprise 2.4

Anchore Announces Availability of Anchore Enterprise 2.4 on Red Hat Marketplace

September 11, 2020
Closing the Cybersecurity Skills Gap with MSPs

Closing the Cybersecurity Skills Gap with MSPs

May 10, 2022


An invaluable resource for all your IT security initiatives and assets.

Knowledge sharing platform for all IT security needs and plans. Peer to peer conversations that leverage industry experts and leaders for ideas, opinions and business insights.

Media@ITSecurityWire.com
Sales@ITSecurityWire.com

Recent Posts

  • Three Potential Solutions to the Cybersecurity Talent Shortage
  • Three SaaS Security Threats and Risks Enterprises Must Address
  • Three Strategies for IT leaders to Deal with Inflation
  • cPacket Networks and AWS to Streamline Cloud Observability
  • Sysdig Open Source Is Expanded to Secure Cloud Services

Visit Our Other Publication

Quick Links

  • About Us
  • News
  • Featured Articles
  • Featured Interview
  • Guest Post
  • Privacy Policy
  • Do Not Sell My Information
An Imprint of OnDot ® Media © | All rights reserved | Privacy Policy