GitLab Patches Multiple Flaws Allowing Arbitrary Code Execution
ID: bfce2067-e28e-5650-bfdc-2d42e63b5908
STIX ID: report--bfce2067-e28e-5650-bfdc-2d42e63b5908
Feed Name: GBHackers
Threat Score
GitLab released patch updates (18.7.1, 18.6.3, 18.5.5) addressing multiple vulnerabilities—most notably high-severity stored and reflected XSS, missing authorization in AI/Duo workflows, DoS and information disclosure—affecting self‑managed instances; administrators are urged to apply the patches promptly and follow upgrade guidance (including expected downtime for singlenode and zero-downtime procedures for multinode) to mitigate integrity, confidentiality, and availability risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
