CVE-2022-1680
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in the absence of 2FA - take over those accounts. It is also possible for the attacker to change the display name and username of the targeted account.
Se ha detectado un problema de toma de posesión de cuentas en GitLab EE afectando a todas las versiones a partir de 11.10 anteriores a 14.9.5, todas las versiones a partir de 14.10 anteriores a 14.10.4 y todas las versiones a partir de 15.0 anteriores a 15.0.1. Cuando es configurado el SAML SSO de grupo, la función SCIM (disponible sólo en las suscripciones Premium+) puede permitir a cualquier propietario de un grupo Premium invitar a usuarios arbitrarios mediante su nombre de usuario y su correo electrónico, y luego cambiar las direcciones de correo electrónico de esos usuarios por medio de SCIM a una dirección de correo electrónico controlada por el atacante y así -en ausencia de 2FA- una toma de control de esas cuentas. También es posible que el atacante cambie el nombre de pantalla y el nombre de usuario de la cuenta objetivo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-12 CVE Reserved
- 2022-06-06 CVE Published
- 2023-12-28 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/363058 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1680.json | 2022-06-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 11.10.0 < 14.9.5 Search vendor "Gitlab" for product "Gitlab" and version " >= 11.10.0 < 14.9.5" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | >= 14.10.0 < 14.10.4 Search vendor "Gitlab" for product "Gitlab" and version " >= 14.10.0 < 14.10.4" | enterprise |
Affected
| ||||||
Gitlab Search vendor "Gitlab" | Gitlab Search vendor "Gitlab" for product "Gitlab" | 15.0.0 Search vendor "Gitlab" for product "Gitlab" and version "15.0.0" | enterprise |
Affected
|