TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)

66 pointsby altharazabout 3 years ago

2 comments

thciprianiabout 3 years ago
To save folks some digging on what exactly this means—it&#x27;s exactly what it sounds like: <a href="https:&#x2F;&#x2F;gitlab.com&#x2F;gitlab-org&#x2F;gitlab&#x2F;-&#x2F;commit&#x2F;e2fb87ec5d4e235d6b83454980cec9c049849a1c#f4d654b98cc11d931e3f77ee61318adc95a52f12" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;gitlab-org&#x2F;gitlab&#x2F;-&#x2F;commit&#x2F;e2fb87ec5d4e23...</a>
评论 #30876409 未加载
评论 #30875039 未加载
krebsonsecurityabout 3 years ago
This appears to be related. One Github user shared an alert they got today, two days after connecting their Github account to Gitlab. Something about an app added to the account. Their Github has 2fa turned on and a very strong password:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;briankrebs&#x2F;status&#x2F;1509910113716514822" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;briankrebs&#x2F;status&#x2F;1509910113716514822</a>