TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)

66 点作者 altharaz大约 3 年前

2 条评论

thcipriani大约 3 年前
To save folks some digging on what exactly this means—it&#x27;s exactly what it sounds like: <a href="https:&#x2F;&#x2F;gitlab.com&#x2F;gitlab-org&#x2F;gitlab&#x2F;-&#x2F;commit&#x2F;e2fb87ec5d4e235d6b83454980cec9c049849a1c#f4d654b98cc11d931e3f77ee61318adc95a52f12" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;gitlab-org&#x2F;gitlab&#x2F;-&#x2F;commit&#x2F;e2fb87ec5d4e23...</a>
评论 #30876409 未加载
评论 #30875039 未加载
krebsonsecurity大约 3 年前
This appears to be related. One Github user shared an alert they got today, two days after connecting their Github account to Gitlab. Something about an app added to the account. Their Github has 2fa turned on and a very strong password:<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;briankrebs&#x2F;status&#x2F;1509910113716514822" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;briankrebs&#x2F;status&#x2F;1509910113716514822</a>