ืฆื•ื•ื™ื™ื˜ืข ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ GitLab ืื™ืŸ ืึท ื•ื•ืึธืš

GitLab ื”ืื˜ ืืจื•ื™ืก ื“ื™ ื•ื•ื™ื™ึทื˜ืขืจ ืกืขืจื™ืข ืคื•ืŸ โ€‹โ€‹ืงืขืจืขืงื˜ื™ื•ื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืฆื• ื–ื™ื™ืŸ ืคึผืœืึทื˜ืคืึธืจืžืข ืคึฟืึทืจ ืึธืจื’ืึทื ื™ื™ื–ื™ื ื’ ืงืึทืœืึทื‘ืขืจื™ื™ื˜ื™ื•ื• ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ - 15.3.2, 15.2.4 ืื•ืŸ 15.1.6, ื•ื•ืึธืก ืขืœื™ืžื™ื ื™ืจืŸ ืึท ืงืจื™ื˜ื™ืฉ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ (CVE-2022-2992) ื•ื•ืึธืก ืึทืœืึทื•ื– ืึทืŸ ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ืึทื“ ื‘ืึทื ื™ืฆืขืจ ืฆื• ืจื™ืžืึธื•ื˜ืœื™ ื•ื™ืกืคื™ืจืŸ ืงืึธื“ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ. ื•ื•ื™ ื“ื™ CVE-2022-2884 ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™, ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึทืจืคืขืกื˜ื™ืงื˜ ืึท ื•ื•ืึธืš ืฆื•ืจื™ืง, ืึท ื ื™ื™ึทืข ืคึผืจืึธื‘ืœืขื ืื™ื– ืคืึธืจืฉื˜ืขืœืŸ ืื™ืŸ ื“ื™ ืึทืคึผื™ ืคึฟืึทืจ ื™ืžืคึผืึธืจื˜ื™ื ื’ ื“ืึทื˜ืŸ ืคึฟื•ืŸ ื“ื™ GitHub ื“ื™ื ืกื˜. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืื•ื™ืš ืืจื•ื™ืก ืื™ืŸ ืจื™ืœื™ืกื™ื– 15.3.1, 15.2.3 ืื•ืŸ 15.1.5, ื•ื•ืึธืก ืคืึทืจืคืขืกื˜ื™ืงื˜ ื“ื™ ืขืจืฉื˜ืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ื“ื™ ืึทืจื™ื™ึทื ืคื™ืจ ืงืึธื“ ืคึฟื•ืŸ GitHub.

ืึทืคึผืขืจื™ื™ืฉืึทื ืึทืœ ื“ืขื˜ืึทื™ืœืก ื–ืขื ืขืŸ ื ืึธืš ื ื™ืฉื˜ ืฆื•ื’ืขืฉื˜ืขืœื˜. ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ื’ืขื•ื•ืขืŸ ื“ืขืจืœืื ื’ื˜ ืฆื• GitLab ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ HackerOne ืก ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื‘ืจื™ื™ื˜ื”ืึทืจืฆื™ืงื™ื™ื˜ ืคึผืจืึธื’ืจืึทื, ืึธื‘ืขืจ ื ื™ื˜ ืขื ืœืขืš ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ืคึผืจืึธื‘ืœืขื, ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื“ื•ืจืš ืืŸ ืื ื“ืขืจ ื‘ืึทื˜ื™ื™ืœื™ืงื˜ืขืจ. ื•ื•ื™ ืึท ื•ื•ืึธืจืงืึทืจืึธื•ื ื“, ืขืก ืื™ื– ืจืขืงืึทืžืขื ื“ื™ื“ ืึทื– ื“ืขืจ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ื“ื™ืกื™ื™ื‘ืึทืœ ื“ื™ ืึทืจื™ื™ึทื ืคื™ืจ ืคึฟื•ื ืงืฆื™ืข ืคึฟื•ืŸ GitHub (ืื™ืŸ ื“ื™ GitLab ื•ื•ืขื‘ ืฆื•ื‘ื™ื ื“: "ืžืขื ื™ื•" -> "ืึทื“ืžื™ืŸ" -> "ืกืขื˜ื˜ื™ื ื’ืก" -> "ืึทืœื’ืขืžื™ื™ื ืข" -> "ื•ื•ื™ื–ืึทื‘ื™ืœื™ื˜ื™ ืื•ืŸ ืึทืงืกืขืก ืงืึธื ื˜ืจืึธืœืก" - > "ื™ืžืคึผืึธืจื˜ ืžืงื•ืจื™ื" -> ื“ื™ืกื™ื™ื‘ืึทืœ "ื’ื™ื˜ื”ื•ื‘").

ืื™ืŸ ืึทื“ื™ืฉืึทืŸ, ื“ื™ ืคืืจื’ืขืœื™ื™ื’ื˜ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื•ื ื’ืขืŸ ืคืึทืจืจื™ื›ื˜ืŸ 14 ืžืขืจ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื–, ืฆื•ื•ื™ื™ ืคื•ืŸ ื•ื•ืึธืก ื–ืขื ืขืŸ ืื ื’ืขืฆื™ื™ื›ื ื˜ ื•ื•ื™ ื’ืขืคืขืจืœืขืš, ืฆืขืŸ ื–ืขื ืขืŸ ืึทืกื™ื™ื ื“ ืึท ืžื™ื˜ืœ ืžื“ืจื’ื” ืคื•ืŸ ื’ืขืคืึทืจ, ืื•ืŸ ืฆื•ื•ื™ื™ ื–ืขื ืขืŸ ืื ื’ืขืฆื™ื™ื›ื ื˜ ื•ื•ื™ ื’ื•ื˜. ื“ื™ ืคืืœื’ืขื ื“ืข ื–ืขื ืขืŸ ืื ืขืจืงืขื ื˜ ื•ื•ื™ ื’ืขืคืขืจืœืขืš: ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ CVE-2022-2865, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืœื™ื™ื’ืŸ ื“ื™ื™ืŸ ืื™ื™ื’ืขื ืข ื“ื–ืฉืึทื•ื•ืึทืกืงืจื™ืคึผื˜ ืงืึธื“ ืฆื• ื‘ืœืขื˜ืขืจ ื’ืขื•ื•ื™ื–ืŸ ืฆื• ืื ื“ืขืจืข ื™ื•ื–ืขืจื– ื“ื•ืจืš ืžืึทื ื™ืคึผื™ืึทืœื™ื™ืฉืึทืŸ ืคื•ืŸ ืงืึธืœื™ืจ ืœืึทื‘ืขืœืก, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ CVE-2022-2527, ื•ื•ืึธืก ืžืื›ื˜ ืขืก ืžืขื’ืœืขืš ืฆื• ืคืึทืจื‘ื™ื™ึทื˜ืŸ ื“ื™ื™ืŸ ืื™ื ื”ืึทืœื˜ ื“ื•ืจืš ื“ื™ ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’ ืคืขืœื“ ืื™ืŸ ื“ื™ ื™ื ืกื™ื“ืขื ืฅ ื•ื•ืึธื’ ื˜ื™ื™ืžืœื™ื™ืŸ). ืžืขืกื™ืง ืฉื˜ืจืขื ื’ืงื™ื™ึทื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ื–ืขื ืขืŸ ื‘ืคึฟืจื˜ ืฉื™ื™ึทื›ื•ืช ืฆื• ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืคื•ืŸ ืึธืคึผืœื™ื™ืงืขื ื•ื ื’ ืคื•ืŸ ื“ื™ื ืกื˜.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’