HIGH

CVE-2022-4037

Gitlab GitLab 2023-01-12 CVSS v3.1
CVSS
8.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.

Summary dbcve.org

A race condition in GitLab's OAuth identity provider implementation allows attackers to forge verified email addresses during the OAuth authentication flow. When GitLab is configured as an OAuth provider for third-party applications, the timing vulnerability can be exploited to associate an attacker's controlled email with a victim's account, enabling account takeover of those third-party services.

Mitigation

Upgrade GitLab installations to version 15.5.7, 15.6.4, 15.7.2 or later. If upgrade is not immediately possible, disable GitLab as an OAuth identity provider until patching can be completed.

Weakness (CWE)

CWE-362 Race Condition

EPSS Score

0.64%
Probability of exploitation in next 30 days
49.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE