Live data from Hacker News

GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

hackerone.com

11–12 of 12 posts

Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

#11
post #3

Very proud of our security team for the responsive communication and ensuring the issue is made public https://gitlab.com/gitlab-org/gitlab-ce/issues/54189#note_12...

Appreciate the transparency. Was there any evidence of exploitation found? At least the researcher should have been identified as true positive compromising their own account to ensure post mortem investigation was correct and no other customers were impacted/exploited by a real adversary.

Re: GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

#12
It would be really cool to see a blog post on how this was handled internally. IR team notification, escalation paths, internal verification, how the product team was notified, determining priority, how you decide when to disclose vs not, etc.
Post reply on HN