ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ื‘-GitLab

ืขื“ื›ื•ื ื™ื ืžืชืงื™ื ื™ื ืœืคืœื˜ืคื•ืจืžืช ื”ืคื™ืชื•ื— ื”ืฉื™ืชื•ืคื™ GitLab 15.3.1, 15.2.3 ื•-15.1.5 ืคื•ืชืจื™ื ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2022-2884) ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืื•ืžืช ืขื ื’ื™ืฉื” ืœ-API ืœื™ื™ื‘ื•ื โ€‹โ€‹ื ืชื•ื ื™ื ืž-GitHub ืœื‘ืฆืข ืžืจื—ื•ืง ืงื•ื“ ื‘- ื”ืฉืจืช . ื˜ืจื ื ืžืกืจื• ืคืจื˜ื™ื ืชืคืขื•ืœื™ื™ื. ื”ืคื’ื™ืขื•ืช ื–ื•ื”ืชื” ืขืœ ื™ื“ื™ ื—ื•ืงืจ ืื‘ื˜ื—ื” ื›ื—ืœืง ืžืชื•ื›ื ื™ืช ื”ืคื’ื™ืขื•ืช ืฉืœ HackerOne.

ื›ื“ืจืš ืœืขืงื™ืคืช ื”ื‘ืขื™ื”, ืžื•ืžืœืฅ ืฉื”ืžื ื”ืœืŸ ื™ื‘ื˜ืœ ืืช ืคื•ื ืงืฆื™ื™ืช ื”ื™ื™ื‘ื•ื โ€‹โ€‹ืž-GitHub (ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ GitLab: "ืชืคืจื™ื˜" -> "ืื“ืžื™ืŸ" -> "ื”ื’ื“ืจื•ืช" -> "ื›ืœืœื™" -> "ื‘ืงืจื•ืช ื’ื™ืฉื” ื•ื’ื™ืฉื”" - > "ื™ื™ื‘ื•ื โ€‹โ€‹ืžืงื•ืจื•ืช" -> ื”ืฉื‘ืช ืืช "GitHub").

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”