Live data from Hacker News

GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

hackerone.com

1–10 of 12 posts

Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

#5
post #3

Very proud of our security team for the responsive communication and ensuring the issue is made public https://gitlab.com/gitlab-org/gitlab-ce/issues/54189#note_12...

Indeed, fantastic job!

Credit where credit's due to HackerOne co-founder jobert, too. Seems he's made a decent living [0] out of making GitLab more secure.

On the flipside, as a GitLab user, I'm glad to see you guys are so generous with bounties to encourage more detailed (and fascinating) reports like these. :)

[0] https://hackerone.com/jobert?order_direction=DESC&order_fiel...

Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

#6
Thank you for submitting this report. We will investigate the issue as soon as possible. Due to our current workload, we will get back within 20 business days with an update.

Best regards, GitLab Security Team

Luckily someone looked at this sooner than a month later! You can see where Google's project zero came in - push for folks to prioritize security.

Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

#7

Thank you for submitting this report. We will investigate the issue as soon as possible. Due to our current workload, we will get back within 20 business days with an update. Best regards, GitLab Security Team Luckily someone looked at this sooner than a month later! You can see where Google's project zero came in - push for folks to prioritize security.

Underpromise and overdeliver?

Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

#9

Thank you for submitting this report. We will investigate the issue as soon as possible. Due to our current workload, we will get back within 20 business days with an update. Best regards, GitLab Security Team Luckily someone looked at this sooner than a month later! You can see where Google's project zero came in - push for folks to prioritize security.

I would assume that everything is screened as soon as it comes in. Then anything that looks remotely urgent/dangerous is escalated accordingly. Anything else is left pending. Under promise, over deliver via the message.

Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

#10

Thank you for submitting this report. We will investigate the issue as soon as possible. Due to our current workload, we will get back within 20 business days with an update. Best regards, GitLab Security Team Luckily someone looked at this sooner than a month later! You can see where Google's project zero came in - push for folks to prioritize security.

Thank you for your feedback and comment. The message is generated by our automation capability. We want to keep hackers engaged by making sure they know that the issue is successfully submitted. We usually review the report sooner than promised, but want to set expectations accordingly. The automation calculates the number of business days based on current number of reports pending, so it is not always going to be the same message.
Post reply on HN