Over View - Your Daily News Source
  • Home
  • News
    • Business
    • Politics
    • Science
  • Lifestyle
    • Food
    • Travel
    • Health
    • Fashion
  • Entertainment
    • Entertainment
    • Sports
  • Tech
No Result
View All Result
  • Home
  • News
    • Business
    • Politics
    • Science
  • Lifestyle
    • Food
    • Travel
    • Health
    • Fashion
  • Entertainment
    • Entertainment
    • Sports
  • Tech
No Result
View All Result
Over View - Your Daily News Source
No Result
View All Result
Home Tech

GitLab releases emergency security patch, tells users to update immediately

May 25, 2023
in Tech
0
GitLab releases emergency security patch, tells users to update immediately
  1. Home
  2. News
  3. Pro
Zero-day attack



(Image credit: Shutterstock)
(Image credit: Shutterstock.com)

GitLab has published a fix for a critical security vulnerability found in two of its products, with users told to apply the patch immediately. 

GitLab is a DevOps software package allowing users to develop, secure, and operate software used by developer teams that need to manage their code remotely, and has some 30 million registered users, including a million paying customers. 

The company recently discovered a path traversal flaw, tracked as CVE-2023-2825. This vulnerability allows unauthenticated attackers to read arbitrary files on the server, when certain conditions are met. As a result, threat actors could read sensitive data such as proprietary software code, user credentials, and more, from vulnerable endpoints. No more details are available at this time, with GitLab saying it would say more a month after the patch.

Silver lining

The flaw was given a severity score of 10/10, and was found in GitLab Community Edition (CE) and Enterprise Edition (EE) version 16.0.0. Not all older versions are affected, but GitLab still recommends users apply the fix and bring the tools up to version 16.0.1.

“We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possible,” GitLab said in a security advisory, published together with the fix. “When no specific deployment type (omnibus, source code, helm chart, etc.) of a product is mentioned, this means all types are affected.”

To exploit the flaw, there needs to be an attachment in a public project nested within at least five groups, the researchers said. The silver lining here is that this isn’t the structure found in all GitHub projects. Nevertheles, the company urged everyone to apply the fix, as there are no workarounds for the flaw, and there’s simply too much at stake.

To update the GitLab installation, user should follow the instructions found here. 

  • To keep your premises secure, make sure to grab one of the best firewalls right now

Via: BleepingComputer

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Most Popular

Read More

Previous Post

Microsoft is finally introducing the feature that’ll make me upgrade to Windows 11

Next Post

Barracuda warns users about possible email compromise attacks

Next Post
Barracuda warns users about possible email compromise attacks

Barracuda warns users about possible email compromise attacks

Stay Connected

  • Trending
  • Comments
  • Latest
Price of Micah Parsons’s Haircut Just Went Up Tremendously

Price of Micah Parsons’s Haircut Just Went Up Tremendously

November 23, 2022
German home prices to fall 3.5% next year as buyers feel the pinch

German home prices to fall 3.5% next year as buyers feel the pinch

November 23, 2022
Tesla’s shares hit a two-year low as investors worry about Elon Musk’s focus on Twitter and a growing list of bad news

Tesla’s shares hit a two-year low as investors worry about Elon Musk’s focus on Twitter and a growing list of bad news

November 25, 2022
Black Friday Apple deals live: record-low prices on Airpods, iPads, Apple Watch

Black Friday Apple deals live: record-low prices on Airpods, iPads, Apple Watch

November 25, 2022
The best genderless skin care products

The best genderless skin care products

The U.S. Will Cut Emissions In An Effort To Avoid ‘Climate Hell,’ Biden Says

The U.S. Will Cut Emissions In An Effort To Avoid ‘Climate Hell,’ Biden Says

Truly Heroic: Meet The Inspirational Owner Of Norway’s Esports Powerhouse

Truly Heroic: Meet The Inspirational Owner Of Norway’s Esports Powerhouse

The Untold Story Behind Emax, The Cryptocurrency Kim Kardashian Got Busted For Hyping

The Untold Story Behind Emax, The Cryptocurrency Kim Kardashian Got Busted For Hyping

WWE Hall of Famer Who Recently Slammed Trish Stratus Shows off Her “Natural” Jacked-Up Physique at 60 Years of Age

WWE Hall of Famer Who Recently Slammed Trish Stratus Shows off Her “Natural” Jacked-Up Physique at 60 Years of Age

June 4, 2023
Dwayne Johnson Left Stunned by a 23-Year Old “Hardest Worker in the Room”; Expresses His Desire to Work Together With Her – “Sky Is the Limit”

Dwayne Johnson Left Stunned by a 23-Year Old “Hardest Worker in the Room”; Expresses His Desire to Work Together With Her – “Sky Is the Limit”

June 4, 2023
Mike Tyson Opens Up About His “Pimp” Father While Explaining “Beautiful Process of Dying” When Asked How Would He Want His Kids to Remember Him

Mike Tyson Opens Up About His “Pimp” Father While Explaining “Beautiful Process of Dying” When Asked How Would He Want His Kids to Remember Him

June 4, 2023
“Happy Shield Break Up Day”: Fans Go Wild as Seth Rollins Reveals His Future Plans as World Heavyweight Champion

“Happy Shield Break Up Day”: Fans Go Wild as Seth Rollins Reveals His Future Plans as World Heavyweight Champion

June 4, 2023

Recent News

WWE Hall of Famer Who Recently Slammed Trish Stratus Shows off Her “Natural” Jacked-Up Physique at 60 Years of Age

WWE Hall of Famer Who Recently Slammed Trish Stratus Shows off Her “Natural” Jacked-Up Physique at 60 Years of Age

June 4, 2023
Dwayne Johnson Left Stunned by a 23-Year Old “Hardest Worker in the Room”; Expresses His Desire to Work Together With Her – “Sky Is the Limit”

Dwayne Johnson Left Stunned by a 23-Year Old “Hardest Worker in the Room”; Expresses His Desire to Work Together With Her – “Sky Is the Limit”

June 4, 2023
Mike Tyson Opens Up About His “Pimp” Father While Explaining “Beautiful Process of Dying” When Asked How Would He Want His Kids to Remember Him

Mike Tyson Opens Up About His “Pimp” Father While Explaining “Beautiful Process of Dying” When Asked How Would He Want His Kids to Remember Him

June 4, 2023
“Happy Shield Break Up Day”: Fans Go Wild as Seth Rollins Reveals His Future Plans as World Heavyweight Champion

“Happy Shield Break Up Day”: Fans Go Wild as Seth Rollins Reveals His Future Plans as World Heavyweight Champion

June 4, 2023

No Result
View All Result
  • Entertainment
    • Entertainment
    • Sports
  • Lifestyle
    • Fashion
    • Health
    • Travel
    • Food
  • News
    • Business
    • Politics
    • Science
  • Tech