GitLab RCE Vulnerability: Critical Flaws Expose Default Installations
ID: c7f258ad-eb3f-527b-979d-7b84af8edaa1
STIX ID: report--c7f258ad-eb3f-527b-979d-7b84af8edaa1
Feed Name: CyberNexora News
Executive Summary: A critical remote code execution vulnerability was disclosed in GitLab's notebook diff processing due to two flaws in the Oj Ruby JSON parser; specially crafted .ipynb diffs can trigger arbitrary command execution on affected self-managed GitLab instances (Oj 3.13.0–3.17.1 and multiple GitLab release ranges). GitLab.com was patched, but self-managed administrators are urged to upgrade to the fixed GitLab and Oj versions immediately, audit notebook commits and permissions, and monitor for the provided IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
