GitLab – INDIA NEWS http://www.indiavpn.org News Blog Tue, 30 Jan 2024 16:37:57 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.1 URGENT: Upgrade GitLab – Critical Workspace Creation Flaw Allows File Overwrite http://www.indiavpn.org/2024/01/30/urgent-upgrade-gitlab-critical-workspace-creation-flaw-allows-file-overwrite/ http://www.indiavpn.org/2024/01/30/urgent-upgrade-gitlab-critical-workspace-creation-flaw-allows-file-overwrite/#respond Tue, 30 Jan 2024 16:37:57 +0000 https://www.indiavpn.org/2024/01/30/urgent-upgrade-gitlab-critical-workspace-creation-flaw-allows-file-overwrite/ [ad_1]

Jan 30, 2024NewsroomDevSecOps / Vulnerability

GitLab

GitLab once again released fixes to address a critical security flaw in its Community Edition (CE) and Enterprise Edition (EE) that could be exploited to write arbitrary files while creating a workspace.

Tracked as CVE-2024-0402, the vulnerability has a CVSS score of 9.9 out of a maximum of 10.

“An issue has been discovered in GitLab CE/EE affecting all versions from 16.0 prior to 16.5.8, 16.6 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 which allows an authenticated user to write files to arbitrary locations on the GitLab server while creating a workspace,” GitLab said in an advisory released on January 25, 2024.

Cybersecurity

The company also noted patches for the bug have been backported to 16.5.8, 16.6.6, 16.7.4, and 16.8.1.

Also resolved by GitLab are four medium-severity flaws that could lead to a regular expression denial-of-service (ReDoS), HTML injection, and the disclosure of a user’s public email address via the tags RSS feed.

The latest update arrives two weeks after the DevSecOps platform shipped fixes to close out two critical shortcomings, including one that could be exploited to take over accounts without requiring any user interaction (CVE-2023-7028, CVSS score: 10.0).

Users are advised to upgrade the installations to a patched version as soon as possible to mitigate potential risks. GitLab.com and GitLab Dedicated environments are already running the latest version.

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
http://www.indiavpn.org/2024/01/30/urgent-upgrade-gitlab-critical-workspace-creation-flaw-allows-file-overwrite/feed/ 0
Urgent: GitLab Releases Patch for Critical Vulnerabilities http://www.indiavpn.org/2024/01/12/urgent-gitlab-releases-patch-for-critical-vulnerabilities/ http://www.indiavpn.org/2024/01/12/urgent-gitlab-releases-patch-for-critical-vulnerabilities/#respond Fri, 12 Jan 2024 19:03:34 +0000 https://www.indiavpn.org/2024/01/12/urgent-gitlab-releases-patch-for-critical-vulnerabilities/ [ad_1]

Jan 12, 2024NewsroomDevSecOps / Software security

Gitlab Vulnerabilities

GitLab has released security updates to address two critical vulnerabilities, including one that could be exploited to take over accounts without requiring any user interaction.

Tracked as CVE-2023-7028, the flaw has been awarded the maximum severity of 10.0 on the CVSS scoring system and could facilitate account takeover by sending password reset emails to an unverified email address.

The DevSecOps platform said the vulnerability is the result of a bug in the email verification process, which allowed users to reset their password through a secondary email address.

Cybersecurity

It affects all self-managed instances of GitLab Community Edition (CE) and Enterprise Edition (EE) using the below versions –

  • 16.1 prior to 16.1.6
  • 16.2 prior to 16.2.9
  • 16.3 prior to 16.3.7
  • 16.4 prior to 16.4.5
  • 16.5 prior to 16.5.6
  • 16.6 prior to 16.6.4
  • 16.7 prior to 16.7.2

GitLab said it addressed the issue in GitLab versions 16.5.6, 16.6.4, and 16.7.2, in addition to backporting the fix to versions 16.1.6, 16.2.9, 16.3.7, and 16.4.5. The company further noted the bug was introduced in 16.1.0 on May 1, 2023.

Cybersecurity

“Within these versions, all authentication mechanisms are impacted,” GitLab said. “Additionally, users who have two-factor authentication enabled are vulnerable to password reset but not account takeover as their second authentication factor is required to login.”

Also patched by GitLab as part of the latest update is another critical flaw (CVE-2023-5356, CVSS score: 9.6), which permits a user to abuse Slack/Mattermost integrations to execute slash commands as another user.

To mitigate any potential threats, it’s advised to upgrade the instances to a patched version as soon as possible and enable 2FA, if not already, particularly for users with elevated privileges.

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

]]>
http://www.indiavpn.org/2024/01/12/urgent-gitlab-releases-patch-for-critical-vulnerabilities/feed/ 0