17 vulnerabilities in GitLab

Corrective updates for the GitLab collaborative development platform have been released — versions 17.3.2, 17.2.5, and 17.1.7, addressing 17 vulnerabilities. One vulnerability has been assigned a critical severity level (9.9 out of 10), 3 are high, 11 are moderate, and 2 are low. The critical vulnerability (CVE-2024-6678) allows pipeline jobs to be executed under a different user, enabling an attacker to gain access to that user's internal repositories and private projects.

Vulnerability details have been reported to GitLab as part of the ongoing bug bounty program on HackerOne. Detailed information about the vulnerability is planned to be disclosed 30 days after the fix is published.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster