Comment on GitLab users warned of flaw that allows file overwrite — so update now

doeknius_gloek@discuss.tchncs.de ⁨4⁩ ⁨months⁩ ago

This patch is a week old, so hopefully you have already updated.

GitLab seems to have glaring security holes quite often. Surely this is in part because of the open source codebase and their bug bounty program, which incentivizes researchers to look for these flaws. I’m still baffled sometimes. I’ve read about a lot of > 9.0 CVEs while maintaining our GitLab instance, there was a 10 only three weeks ago. Thankfully our instance isn’t public.

source
Sort:hotnewtop