ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ืฉื ื™ื™ื” ื‘-GitLab ืชื•ืš ืฉื‘ื•ืข

GitLab ืคืจืกืžื” ืืช ืกื“ืจืช ื”ืขื“ื›ื•ื ื™ื ื”ืžืชืงื ืช ื”ื‘ืื” ืœืคืœื˜ืคื•ืจืžื” ืฉืœื” ืœืืจื’ื•ืŸ ืคื™ืชื•ื— ืฉื™ืชื•ืคื™ - 15.3.2, 15.2.4 ื•-15.1.6, ื”ืžื‘ื˜ืœื•ืช ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช (CVE-2022-2992) ื”ืžืืคืฉืจืช ืœืžืฉืชืžืฉ ืžืื•ืžืช ืœื‘ืฆืข ืžืจื—ื•ืง ืงื•ื“ ืขืœ ื”ืฉืจืช. ื‘ื“ื•ืžื” ืœืคื’ื™ืขื•ืช CVE-2022-2884, ืฉืชื•ืงื ื” ืœืคื ื™ ืฉื‘ื•ืข, ืงื™ื™ืžืช ื‘ืขื™ื” ื—ื“ืฉื” ื‘-API ืœื™ื™ื‘ื•ื โ€‹โ€‹ื ืชื•ื ื™ื ืžืฉื™ืจื•ืช GitHub. ื”ืคื’ื™ืขื•ืช ืžื•ืคื™ืขื” ื’ื ื‘ืžื”ื“ื•ืจื•ืช 15.3.1, 15.2.3 ื•-15.1.5, ืฉืชื™ืงื ื• ืืช ื”ืคื’ื™ืขื•ืช ื”ืจืืฉื•ื ื” ื‘ืงื•ื“ ื”ื™ื™ื‘ื•ื โ€‹โ€‹ืž-GitHub.

ื˜ืจื ื ืžืกืจื• ืคืจื˜ื™ื ืชืคืขื•ืœื™ื™ื. ืžื™ื“ืข ืขืœ ื”ืคื’ื™ืขื•ืช ื ืžืกืจ ืœ-GitLab ื›ื—ืœืง ืžืชื•ื›ื ื™ืช ื”-vulnerability bounty ืฉืœ HackerOne, ืืš ื‘ื ื™ื’ื•ื“ ืœื‘ืขื™ื” ื”ืงื•ื“ืžืช, ื”ื•ื ื–ื•ื”ื” ืขืœ ื™ื“ื™ ืžืฉืชืชืฃ ืื—ืจ. ื›ื“ืจืš ืœืขืงื™ืคืช ื”ื‘ืขื™ื”, ืžื•ืžืœืฅ ืฉื”ืžื ื”ืœืŸ ื™ื‘ื˜ืœ ืืช ืคื•ื ืงืฆื™ื™ืช ื”ื™ื™ื‘ื•ื โ€‹โ€‹ืž-GitHub (ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ GitLab: "ืชืคืจื™ื˜" -> "ืื“ืžื™ืŸ" -> "ื”ื’ื“ืจื•ืช" -> "ื›ืœืœื™" -> "ื‘ืงืจื•ืช ื ืจืื•ืช ื•ื’ื™ืฉื”" - > "ื™ื™ื‘ื•ื โ€‹โ€‹ืžืงื•ืจื•ืช" -> ื”ืฉื‘ืช ืืช "GitHub").

ื‘ื ื•ืกืฃ, ื”ืขื“ื›ื•ื ื™ื ื”ืžื•ืฆืขื™ื ืžืชืงื ื™ื 14 ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื ื•ืกืคื•ืช, ืฉืชื™ื™ื ืžื”ืŸ ืžืกื•ืžื ื•ืช ื›ืžืกื•ื›ื ื•ืช, ืขืฉืจ ืžื•ืงืฆื•ืช ื‘ืจืžืช ืกื›ื ื” ื‘ื™ื ื•ื ื™ืช ื•ืฉืชื™ื™ื ืžืกื•ืžื ื•ืช ื›ืฉืคื™ืจื•ืช. ื”ื“ื‘ืจื™ื ื”ื‘ืื™ื ืžื•ื›ืจื™ื ื›ืžืกื•ื›ื ื™ื: ืคื’ื™ืขื•ืช CVE-2022-2865, ื”ืžืืคืฉืจืช ืœืš ืœื”ื•ืกื™ืฃ ืงื•ื“ JavaScript ืžืฉืœืš ืœื“ืคื™ื ื”ืžื•ืฆื’ื™ื ืœืžืฉืชืžืฉื™ื ืื—ืจื™ื ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื” ืฉืœ ืชื•ื•ื™ื•ืช ืฆื‘ืข, ื•ื›ืŸ ืคื’ื™ืขื•ืช CVE-2022-2527, ื”ืžืืคืฉืจืช ื”ื—ืœืฃ ืืช ื”ืชื•ื›ืŸ ืฉืœืš ื“ืจืš ืฉื“ื” ื”ืชื™ืื•ืจ ื‘ืฆื™ืจ ื”ื–ืžืŸ ืฉืœ ืกื•ืœื ืื™ืจื•ืขื™ื). ืคื’ื™ืขื•ืช ื‘ื—ื•ืžืจื” ื‘ื™ื ื•ื ื™ืช ืงืฉื•ืจื•ืช ื‘ืขื™ืงืจ ืœืืคืฉืจื•ืช ืฉืœ ืžื ื™ืขืช ืฉื™ืจื•ืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”