GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations
ID: d1189709-03df-5e2e-8de4-5e3a8b74b638
STIX ID: report--d1189709-03df-5e2e-8de4-5e3a8b74b638
Feed Name: cybersecurityNews.com
A researcher from Depthfirst disclosed an exploit chain combining two long-standing memory-safety flaws in the Oj C-based Ruby JSON parser used by GitLab that allows an authenticated user with push and diff-view access to achieve remote code execution as the "git" user. The chain abuses an unchecked nesting-stack write and a 16-bit key-length pointer leak to corrupt a parser callback pointer and defeat ASLR, enabling arbitrary command execution and potential exposure of source code, Rails secrets, and internal services; affected GitLab and Oj versions are listed and patches were released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
