Security News > 2016 > November > GitLab plugs critical flaw in its code repository manager software (Help Net Security)

GitLab plugs critical flaw in its code repository manager software (Help Net Security)
2016-11-04 15:25

GitLab (the company) has pushed out security updates for both the Community Edition (CE) and Enterprise Edition (EE) of the GitLab software, fixing a critical security flaw in the “import/export project” feature. “This feature did not properly check for symbolic links in user-provided archives and therefore it was possible for an authenticated user to retrieve the contents of any file accessible to the GitLab service account. This included sensitive files such as those that contain … More →


News URL

http://feedproxy.google.com/~r/HelpNetSecurity/~3/l5EpaWnLexY/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Gitlab 10 47 706 231 57 1041