Tuesday, September 10, 2024
HomeCVE/vulnerabilityUnauthenticated RCE Flaw in Gitlab Exploited Widely by Hackers

Unauthenticated RCE Flaw in Gitlab Exploited Widely by Hackers

Published on

Cybersecurity researchers from Rapid7 have warned recently that a critical remote code execution (RCE) vulnerability has been found in the currently patched GitLab web interface. And this vulnerability is actively exploited in cyberattacks, making many Internet-connected GitLab instances vulnerable to attack. 

While this vulnerability has been tracked as CVE-2021-22205, and it is an unauthenticated remote code execution (RCE) vulnerability.

After investigating it thoroughly, it has been claimed that this issue is related to improper validation of user-supplied images that are commencing arbitrary code execution remotely. 

- Advertisement - EHA
  • CVE: CVE-2021-22205
  • Vendor Advisory: GitLab Advisory
  • IVM Content: Evaluating
  • Patching Urgency: ASAP
  • Last Update: November 1, 2021

Here we have mentioned all the patched versions below:-

  • 13.10.3
  • 13.9.6
  • 13.8.8

Exploit in the wild

When the threat actors first noted some glimpse of this attack that they have initially commenced exploiting internet-facing GitLab servers in June 2021, with the motive of creating new users and giving them all the admin rights.

Apart from this. in this exploit the threat actors don’t require to verify or use a CSRF token; not only this, but they also don’t require a valid HTTP endpoint to use the exploit.

Despite the availability of patches for more than six months, there is only 21% of the 60,000 internet-connected GitLab installations are fully patched for this particular issue.

However, the remaining 50% are still acknowledged to be vulnerable to RCE attacks. Therefore, the security experts have suggested each, and every user upgrades their GitLab to the most advanced version as soon as possible.

  • 21% of installs are fully patched against this issue.
  • 50% of installs are not patched against this issue.
  • 29% of installs may or may not be vulnerable.

Mitigation

However, Rapid7’s emergent threat response team has provided a full technical analysis of CVE-2021-22205. And they have strongly recommended all the GitLab users immediately update their vulnerable version to the latest version of GitLab.

Moreover, GitLab should not be used as a direct internet-facing service, in case if any users need to access their GitLab from the internet, they should consider placing it behind a VPN.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Chinese Hackers Using Open Source Tools To Launch Cyber Attacks

Three Chinese state-backed threat groups, APT10, GALLIUM, and Stately Taurus, have repeatedly employed a...

Small Business, Big Threats: INE Security Launches Initiative to Train SMBs to Close a Critical Skills Gap

As cyber threats grow, small to medium-sized businesses (SMBs) are disproportionately targeted. According to...

Researchers Details Attacks On Air-Gaps Computers To Steal Data

The air-gap data protection method isolates local networks from the internet to mitigate cyber...

Beware Of Malicious Chrome Extension That Delivers Weaponized ZIP Archive

In August 2024, researchers detected a malicious Google Chrome browser infection that led to...

Free Webinar

Decoding Compliance | What CISOs Need to Know

Non-compliance can result in substantial financial penalties, with average fines reaching up to $4.5 million for GDPR breaches alone.

Join us for an insightful panel discussion with Chandan Pani, CISO - LTIMindtree and Ashish Tandon, Founder & CEO – Indusface, as we explore the multifaceted role of compliance in securing modern enterprises.

Discussion points

The Role of Compliance
The Alphabet Soup of Compliance
Compliance
SaaS and Compliance
Indusface's Approach to Compliance

More like this

CISA Issues Warning About Three Actively Exploited Vulnerabilities in the Wild

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about three...

Akira Ransomware Actively Exploiting SonicWall firewall RCE Vulnerability

SonicWall disclosed a critical remote code execution vulnerability (CVE-2024-40766) in SonicOS on August 22nd,...

IBM webMethods Integration Server Vulnerabilities Exposes Systems to Arbitrary Command Execution

Critical vulnerabilities have been identified, potentially exposing systems to arbitrary command execution.These vulnerabilities,...