Vulnerability in GitLab Allowing Pipeline Jobs to Run Under Another User

Corrective updates for the collaborative development platform GitLab 17.1.1, 17.0.3, 16.11.5, 16.10.8, 16.9.9, 16.8.8, 16.7.8, and 16.6.8 have been released, addressing 14 vulnerabilities. One of the issues (CVE-2024-5655), which appears starting from GitLab release 15.8, has been assigned a critical severity level. This vulnerability allows running continuous integration pipeline jobs under an arbitrary user. Executing one's work in the context of another user can enable an attacker to access that user's internal repositories and private projects.

Vulnerability details have been reported to GitLab as part of the ongoing bug bounty program on HackerOne. Detailed information about the vulnerability is planned to be disclosed 30 days after the fix is published.

Additionally, it is noteworthy that the released GitLab updates have fixed three vulnerabilities rated as high severity: JavaScript code injection (XSS) in commit notes, the organization of calls to the GraphQL API on behalf of the victim when opening a specially crafted page (CSRF), and the leakage of content from private repositories through the use of search in public projects.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster