GitLab has released a critical security update for several versions of its platform, including versions 17.6.2, 17.5.4, and 17.4.6 for both Community and Enterprise Editions. This update fixes vulnerabilities that could result in account takeovers, denial of service attacks, and data leaks.
CVE-2024-11274 (CVSS 8.7) is a critical vulnerability that permits the injection of Network Error Logging (NEL) headers in Kubernetes proxy responses, risking user session data exfiltration. This could allow attackers to steal session data and access accounts without permission.
By infosecbulletin
/ Wednesday , January 22 2025
Fortinet customers must apply the latest updates, as almost 50,000 management interfaces remain vulnerable to the latest zero-day exploit. The...
Read More
By infosecbulletin
/ Tuesday , January 21 2025
Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
By infosecbulletin
/ Tuesday , January 21 2025
Ubuntu 22.04 LTS users are advised to update their systems right away due to a crucial security patch from Canonical...
Read More
By infosecbulletin
/ Tuesday , January 21 2025
Attackers are pretending to be Ukraine's Computer Emergency Response Team (CERT-UA) using AnyDesk to access target computers. “Unidentified individuals are...
Read More
By infosecbulletin
/ Tuesday , January 21 2025
Oracle Critical Patch Update Pre-Release Announcement shares details about the upcoming update scheduled for January 21, 2025. Note that this...
Read More
By infosecbulletin
/ Tuesday , January 21 2025
OWASP has released its updated list of the top 10 vulnerabilities in smart contracts for 2025. This guide highlights the...
Read More
By infosecbulletin
/ Monday , January 20 2025
Security researchers have found several vulnerabilities in Azure DevOps that could enable attackers to inject CRLF queries and carry out...
Read More
By infosecbulletin
/ Monday , January 20 2025
Intel Corporation is a leading semiconductor chip manufacturer, employing at least 22 graduates from the Department of Applied Chemistry and...
Read More
By infosecbulletin
/ Sunday , January 19 2025
vpnMentor’s Research Team is monitoring the potential TikTok ban in the U.S., driven by national security and data privacy issues....
Read More
By infosecbulletin
/ Saturday , January 18 2025
MITRE launched D3FENDTM 1.0, a cybersecurity framework that provides a vocabulary and understanding of the cyber domain. D3FEND 1.0, funded...
Read More
CVE-2024-8233 (CVSS 7.5) allows attackers to perform denial of service attacks by repeatedly sending unauthenticated requests for diff-files. All GitLab versions from 9.4 are affected, making it urgent for users to update.
The update also addresses several medium and low-severity vulnerabilities, including:
CI_JOB_TOKEN Exploitation:
Attackers could potentially use stolen CI_JOB_TOKENs to gain access to user sessions.
Open Redirects and Path Traversal:
These vulnerabilities can be used for phishing and data leaks.
Cross-Site Scripting (XSS) and HTML Injection:
Improper output encoding and other vulnerabilities can allow XSS attacks if Content Security Policy (CSP) is not enabled.
Information Leaks:
Unauthorized users could access sensitive information, like project names and incident details.
GitLab urges all users to update to the latest versions immediately to address security risks. The company thanks security researchers for reporting these vulnerabilities through its HackerOne bug bounty program.