0x

guest@0xbase ~$ read-only mode. Posting requires EU location.

GitLab Multiple Versions: Critical Vulnerabilities Patched (advisories.ncsc.nl)

· 73d ago · Report · Spotlight this ·
0xBASE INTEL BRIEF
  • Authenticated users could access Jira issues outside their project due to insufficient access control.
  • Unauthenticated users could cause denial-of-service via specially crafted requests missing CSRF protection.
  • Developers with proper rights could delete protected container registry tags and bypass package protection rules.

"GitLab Inc. has fixed multiple vulnerabilities affecting CE and EE from version 8.3 to 18.11.3, including access control flaws, XSS, DoS, and authentication bypasses. Attackers can exploit these to access internal hosts, delete protected registry tags, or enumerate private group memberships. Upgrading to patched versions is recommended."

Discussion Matrix

0 segments

no comments yet.