Security News > 2021 > November > Over 30,000 GitLab servers still unpatched against critical bug

Over 30,000 GitLab servers still unpatched against critical bug
2021-11-02 17:46

A critical unauthenticated, remote code execution GitLab flaw fixed on April 14, 2021, remains exploitable, with over 50% of deployments remaining unpatched.

Hackers first started exploiting internet-facing GitLab servers in June 2021 to create new users and give them admin rights.

According to a report published by Rapid7, at least 50% of the 60,000 internet-facing GitLab installations they found are not patched against the critical RCE flaw fixed six months ago.

Any versions earlier than that and down to 11.9 are vulnerable to exploitation whether you're using GitLab Enterprise Edition or GitLab Community Edition.

For more details on how to update GitLab, check out this dedicated portal.

To ensure that your GitLab instance isn't vulnerable to exploitation, you can check its response to POST requests that attempt to exploit ExifTool's mishandling of image files.


News URL

https://www.bleepingcomputer.com/news/security/over-30-000-gitlab-servers-still-unpatched-against-critical-bug/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Gitlab 10 47 706 232 57 1042