ืคื’ื™ืขื•ืช ื‘-GitLab ื”ืžืืคืฉืจืช ืœื”ืจื™ืฅ ืืช ื”ืงื•ื“ ื‘ืขืช ื‘ื ื™ื™ื” ื‘-CI ืฉืœ ื›ืœ ืคืจื•ื™ืงื˜

ืคื•ืจืกืžื• ืขื“ื›ื•ื ื™ื ืžืชืงื ื™ื ืœืคืœื˜ืคื•ืจืžื” ืœืืจื’ื•ืŸ ืคื™ืชื•ื— ืฉื™ืชื•ืคื™ - GitLab 15.11.2, 15.10.6 ื•-15.9.7, ืืฉืจ ืžื‘ื˜ืœื™ื ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2023-2478), ื”ืžืืคืฉืจืช ืœื›ืœ ืžืฉืชืžืฉ ืžืื•ืžืช ืœืฆืจืฃ ืžื˜ืคืœ ืจืฆื™ื ืžืฉืœื•. ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื•ืช ืขื ื”-API ืฉืœ GraphQL (ืืคืœื™ืงืฆื™ื” ืœื”ืคืขืœืช ืžืฉื™ืžื•ืช ื‘ืขืช ื”ืจื›ื‘ืช ืงื•ื“ ืคืจื•ื™ืงื˜ ื‘ืžืขืจื›ืช ืื™ื ื˜ื’ืจืฆื™ื” ืจืฆื™ืคื”) ืœื›ืœ ืคืจื•ื™ืงื˜ ื‘ืื•ืชื• ืฉืจืช. ื˜ืจื ื ืžืกืจื• ืคืจื˜ื™ื ืชืคืขื•ืœื™ื™ื. ืžื™ื“ืข ืขืœ ื”ืคื’ื™ืขื•ืช ื ืฉืœื— ืœ-GitLab ื›ื—ืœืง ืžืชื•ื›ื ื™ืช ื”ืคืจืฆื•ืช ืฉืœ HackerOne.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”