CISOOnline

Critical GitLab flaw allows attackers to delete and modify public repos

“WatchTowr was able to reproduce the vulnerability within minutes of its disclosure, armed only with the advisory details and patch,” Jake Knott, principal security researcher at watchTowr, tells CSO. “AI-enabled attackers are unlikely to be far behind.”

GitLab is a popular source code management system and DevOps platform, complete with CI/CD pipelines and security scanning. The fact that users can self-host it on their own servers makes it an attractive alternative to GitHub, especially for organizations, which is why the software comes in two variants, a free Community Edition (CE) and a paid Enterprise Edition (EE).

The code injection vulnerability is very dangerous especially for GitLab instances exposed directly to the internet because it can lead to software supply chain attacks. The flaw allows attackers to rewrite the state of GitLab repositories, forge merge records, ban maintainers, and even delete entire projects. The exploit doesn’t require credentials, user interaction, or special configurations.



Source link