Over 5,300 GitLab servers exposed to zero-click account takeover attacks
Over 5,300 GitLab servers exposed to zero-click account takeover attacks
Over 5,300 GitLab servers exposed to zero-click account takeover attacks
You're viewing a single thread.
We use gitlab ultimate at my work, I'm the main admin of the instance. Like 2 weeks ago when there was the cvss 10 vuln, gitlab sent us a .patch file to apply to the instance instead of releasing a new minor cause they didn't wanna make the vuln public yet. I guess that's coordinated disclosure, but I still found that remarkably jank.