Skip to content
  • CyberSecurity News

Cybernoz – Cybersecurity News

Search

GitLab – GitLab-Runner on Windows `DOCKER_AUTH_CONFIG` container host Command Injection

 Cybernoz  March 28, 2023  Posted in Mix

GitLab - GitLab-Runner on Windows `DOCKER_AUTH_CONFIG` container host Command Injection

HackerOne bug report to GitLab: GitLab-Runner, when running on Windows with a docker executor, is vulnerable to Command Injection via the DOCKER_AUTH_CONFIG build variable. Injected commands are executed on the container host, not within a Docker container, as such could compromise all future builds which are executed by the runner.



Source link

Post navigation

Latitude Financial data breach now impacts 14 million customers →
← Apple security updates fix 33 iPhone vulnerabilities

Latest Posts

  • Salesforce alerts users to potential data exposure via Gainsight OAuth apps
  • Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges
  • Salesforce Confirms Customer Data Was Exposed in Gainsight Breach
  • Experts Warn Of Formula 1 Las Vegas Grand Prix 2025 Scams
  • Operation DreamJob Attacks on Manufacturing via WhatsApp Web – GBHackers Security

Copyright © 2025 Cybernoz - Cybersecurity News

Design by ThemesDNA.com