Critical vulnerability in GitLab

In the corrective updates of the collaborative development platform GitLab 15.3.1, 15.2.3, and 15.1.5, a critical vulnerability (CVE-2022-2884) has been fixed, allowing an authenticated user with access to the API for importing data from GitHub to execute code remotely on the server. Details of the exploitation are not yet provided. The vulnerability was identified by a security researcher as part of the ongoing HackerOne bug bounty program.

As a workaround, administrators are advised to disable the import function from GitHub (in the GitLab web interface: "Menu" -> "Admin" -> "Settings" -> "General" -> "Visibility and access controls" -> "Import sources" -> disable "GitHub").

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster