GitLab has issued a warning about a serious vulnerability in its GitLab Community and Enterprise editions. This vulnerability allows attackers to execute pipeline jobs as if they were another user.
GitLab’s DevSecOps platform is used by more than 30 million registered users, including T-Mobile, Goldman Sachs, Airbus, Lockheed Martin, Nvidia, and UBS. It is also preferred by over 50% of Fortune 100 companies.
By infosecbulletin
/ Monday , October 28 2024
With a festive look and the participation of more than one hundred participants from Bangladesh cyber industry, another successful cyber...
Read More
By infosecbulletin
/ Monday , October 28 2024
Fazle Hassan Anik hacked girls' Facebook accounts to steal sensitive pictures, which he used to blackmail them for money. He...
Read More
By infosecbulletin
/ Sunday , October 27 2024
Bangladeshi Social media posts have raised concerns about unauthorized withdrawals from bank accounts, affecting at least 7 to 8 people...
Read More
By infosecbulletin
/ Friday , October 25 2024
Cybersecurity researcher Jeremiah Fowler found a non-password-protected database with 115,000 records linked to the UN Trust Fund to End Violence...
Read More
By infosecbulletin
/ Friday , October 25 2024
Cisco announced updates on Wednesday to fix a security flaw in its Adaptive Security Appliance (ASA) that is currently being...
Read More
By infosecbulletin
/ Wednesday , October 23 2024
White hat hackers at the Pwn2Own Ireland 2024 contest by Trend Micro's Zero Day Initiative earned $500,000 on the first...
Read More
By infosecbulletin
/ Tuesday , October 22 2024
In today's rapidly changing cybersecurity environment, organizations encounter numerous complex threats targeting endpoints and networks. CrowdStrike and Fortinet have partnered...
Read More
By infosecbulletin
/ Tuesday , October 22 2024
Sophos, based in the UK, is to acquire Secureworks, a Nasdaq-listed company, for $859 million in cash from Dell Technologies....
Read More
By infosecbulletin
/ Monday , October 21 2024
The Internet Archive was breached again, this time through their Zendesk email support platform, following warnings that threat actors had...
Read More
By infosecbulletin
/ Sunday , October 20 2024
In today's changing cybersecurity environment, it's essential to find vulnerabilities in code. Vulnhuntr, an open-source tool on GitHub, uses Large...
Read More
The security update fixed a flaw identified as CVE-2024-6385 with a severity rating of 9.6 out of 10.
ViperSoftX malware secretly uses AutoIT scripting to run PowerShell. It affects GitLab CE/EE versions from 15.8 to 16.11.6, 17.0 to 17.0.4, and 17.1 to 17.1.2. Attackers can exploit this to start a new pipeline as a different user, under specific conditions which GitLab has not yet revealed.
GitLab pipelines are a feature of a system called Continuous Integration/Continuous Deployment (CI/CD). They allow users to run processes and tasks automatically, either at the same time or one after the other, in order to build, test, or deploy changes to the code.
Company released GitLab Community and Enterprise versions 17.1.2, 17.0.4, and 16.11.6 to fix security flaw. Admins are advised to upgrade all installations right away.
“We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possible,” it warned. “GitLab.com and GitLab Dedicated are already running the patched version.”