CVE-2022-4037
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A race condition can lead to verified email forgery and takeover of third-party accounts when using GitLab as an OAuth provider.
Summary dbcve.org
A race condition in GitLab's OAuth identity provider implementation allows attackers to forge verified email addresses during the OAuth authentication flow. When GitLab is configured as an OAuth provider for third-party applications, the timing vulnerability can be exploited to associate an attacker's controlled email with a victim's account, enabling account takeover of those third-party services.
Mitigation
Upgrade GitLab installations to version 15.5.7, 15.6.4, 15.7.2 or later. If upgrade is not immediately possible, disable GitLab as an OAuth identity provider until patching can be completed.