SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-1680

When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an…

HIGH 8.8EPSS 15.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 15.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

An account takeover issue has been discovered in GitLab EE affecting all versions starting from 11.10 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1. When group SAML SSO is configured, the SCIM feature (available only on Premium+ subscriptions) may allow any owner of a Premium group to invite arbitrary users through their username and email, then change those users' email addresses via SCIM to an attacker controlled email address and thus - in the absence of 2FA - take over those accounts. It is also possible for the attacker to change the display name and username of the targeted account.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
15.90% probability · 97th percentile
CISA KEV
Not listed
Affected
gitlab/gitlab
Source
cve@gitlab.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.