Live data from Hacker News

Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)

about.gitlab.com

1–10 of 24 posts

Re: Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)

#4
post #3

To save folks some digging on what exactly this means—it's exactly what it sounds like: https://gitlab.com/gitlab-org/gitlab/-/commit/e2fb87ec5d4e23...

Do they not have a code review process?

https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318

and I actually suspected it was a matter of the change hiding in an absolute sea of diffs, but there's a comment on the file right below the change: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318/...

> (10 Jan, 2022 1 commit) JH need more complex passwords

> (30 Mar, 2022 1 commit) Revert "JH need more complex passwords"

oops

---

In case others are wondering what's up with the JiHu label and its matching "gitlab-jh" group: https://about.gitlab.com/handbook/ceo/chief-of-staff-team/ji...

Re: Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)

#5

To save folks some digging on what exactly this means—it's exactly what it sounds like: https://gitlab.com/gitlab-org/gitlab/-/commit/e2fb87ec5d4e23...

The hardcoded password seems to be:

Gitlab::Password.test_default(21) => "123qweQWE!@#000000000"

Re: Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)

#6
post #4
post #3

Earlier quoted context omitted.

Do they not have a code review process?

https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318 and I actually suspected it was a matter of the change hiding in an absolute sea of diffs, but there's a comment on the file right below the change: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318/... > (10 Jan, 2022 1 commit) JH need more complex passwords > (30 Mar, 2022 1 commit) Revert "JH need more complex passwords" oops --- In case others…

What I find mildly curious, that's also the only place where a length was provided as an argument into `Gitlab::Password.test_default`.

Re: Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)

#7
post #4
post #3

Earlier quoted context omitted.

Do they not have a code review process?

https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318 and I actually suspected it was a matter of the change hiding in an absolute sea of diffs, but there's a comment on the file right below the change: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318/... > (10 Jan, 2022 1 commit) JH need more complex passwords > (30 Mar, 2022 1 commit) Revert "JH need more complex passwords" oops --- In case others…

I thought I had an account there for a while, I don't know how long (2-3 years?), and all of a sudden I got a password reset out of the blue regarding this particular change. No other emails in my history regarding gitlab whatsoever, so it's even possible I didn't have an account at all.

I go over to the website try to login with my gmail account via SSO which fails because I "already have an account". So I proceed to reset password via email alone.

After I'm in it tells me I've had an account since January 22nd 2022. Super unlikely i created the account this year, so I don't know what's going on over there, but it's not accurate bookkeeping.

Re: Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)

#8
This appears to be related. One Github user shared an alert they got today, two days after connecting their Github account to Gitlab. Something about an app added to the account. Their Github has 2fa turned on and a very strong password:

https://twitter.com/briankrebs/status/1509910113716514822

Re: Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)

#9
post #4
post #3

Earlier quoted context omitted.

Do they not have a code review process?

https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318 and I actually suspected it was a matter of the change hiding in an absolute sea of diffs, but there's a comment on the file right below the change: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318/... > (10 Jan, 2022 1 commit) JH need more complex passwords > (30 Mar, 2022 1 commit) Revert "JH need more complex passwords" oops --- In case others…

Is there a better way to catch errors like this?

Looking through the PR it looks like this file was accidentally changed, I assume with a project wide search and replace.

I could easily imagine myself missing this when reviewing the PR "oh it's just changing a whole bunch of specs, go ahead".

Re: Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)

#10
post #9
post #4

Earlier quoted context omitted.

https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318 and I actually suspected it was a matter of the change hiding in an absolute sea of diffs, but there's a comment on the file right below the change: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318/... > (10 Jan, 2022 1 commit) JH need more complex passwords > (30 Mar, 2022 1 commit) Revert "JH need more complex passwords" oops --- In case others…

Is there a better way to catch errors like this? Looking through the PR it looks like this file was accidentally changed, I assume with a project wide search and replace. I could easily imagine myself missing this when reviewing the PR "oh it's just changing a whole bunch of specs, go ahead".

An integration test that creates dummy accounts using every method including SSO and then attempts to bruteforce the password should find “12345678” within an hour.

I think a test like this would also have found the dropbox and macos bugs that let you login to any account by using an empty password:

https://techcrunch.com/2011/06/20/dropbox-security-bug-made-...

https://arstechnica.com/information-technology/2017/11/macos...

Edit: Oh, the password was "123qweQWE!@#000000000". Technically doable with an efficient password cracker that favors common patterns. zxcvbn’s entropy estimate says it will take 10^10.5 guesses. That’s 1 week at 50k/s. That’s a hell of an integration test for most software.

https://lowe.github.io/tryzxcvbn/

Post reply on HN