GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
1–10 of 12 posts
Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
#2Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
#3Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
#4Very proud of our security team for the responsive communication and ensuring the issue is made public https://gitlab.com/gitlab-org/gitlab-ce/issues/54189#note_12...
Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
#5Very proud of our security team for the responsive communication and ensuring the issue is made public https://gitlab.com/gitlab-org/gitlab-ce/issues/54189#note_12...
Credit where credit's due to HackerOne co-founder jobert, too. Seems he's made a decent living [0] out of making GitLab more secure.
On the flipside, as a GitLab user, I'm glad to see you guys are so generous with bounties to encourage more detailed (and fascinating) reports like these. :)
[0] https://hackerone.com/jobert?order_direction=DESC&order_fiel...
Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
#6Best regards, GitLab Security Team
Luckily someone looked at this sooner than a month later! You can see where Google's project zero came in - push for folks to prioritize security.
Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
#7Thank you for submitting this report. We will investigate the issue as soon as possible. Due to our current workload, we will get back within 20 business days with an update. Best regards, GitLab Security Team Luckily someone looked at this sooner than a month later! You can see where Google's project zero came in - push for folks to prioritize security.
Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
#8Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
#9Thank you for submitting this report. We will investigate the issue as soon as possible. Due to our current workload, we will get back within 20 business days with an update. Best regards, GitLab Security Team Luckily someone looked at this sooner than a month later! You can see where Google's project zero came in - push for folks to prioritize security.
Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
#10Thank you for submitting this report. We will investigate the issue as soon as possible. Due to our current workload, we will get back within 20 business days with an update. Best regards, GitLab Security Team Luckily someone looked at this sooner than a month later! You can see where Google's project zero came in - push for folks to prioritize security.