Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update.

Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

European Parliament Member Investigating Spyware Was Hacked With Pegasus

European Parliament Member Investigating Spyware Was Hacked With Pegasus A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile

Linux and Secure Boot certificate expiration

Linux and Secure Boot certificate expiration Source: Hacker News

Meta Files Patent for AI That Can Listen All Day and Track How You’re Feeling

Meta Files Patent for AI That Can Listen All Day and Track How You’re Feeling Meta has filed a patent application for an AI that listens to your voice throughout