GitLab Fixes Flaws That Could Allow Attackers to Hijack User Sessions
ID: e752e22b-ee2f-5d2c-b365-6ab0bf3195f8
STIX ID: report--e752e22b-ee2f-5d2c-b365-6ab0bf3195f8
Feed Name: GBHackers
Threat Score
GitLab released emergency security patches (18.11.1, 18.10.4, 18.9.6) addressing 11 vulnerabilities across Community and Enterprise editions, including three high-severity flaws (CSRF in the GraphQL API, a Web IDE path validation issue enabling arbitrary JavaScript execution, and an XSS in Storybook) that could lead to session hijacking and token exposure; self-managed installations are strongly urged to upgrade immediately while GitLab.com has already been updated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
