GitLab RCE PoC: Why self-managed installations should urgently check for updates

Colleagues, I’d like to draw your attention to a cyber incident of note.
A working GitLab RCE PoC has been published by researchers after the patch was released.
What matters:
• the attack affects self-managed GitLab;
• with push privileges, an authenticated user can execute commands as git;
• the chain exploits an Oj issue and notebook diff rendering.
I recommend checking your version and upgrading to 18.10.8, 18.11.5, or 19.0.2.
Why this matters: even when a fix is already available, the risk remains without proper classification and release verification.
Have you already compared your GitLab installations against these versions?
#GitLab #cybersecurity #Vulnerability #DevSecOps


Latest comments
No comments yet.