Skip to content

Cybernoz – Cybersecurity News

Search

GitLab – GitLab-Runner on Windows `DOCKER_AUTH_CONFIG` container host Command Injection

 Cybernoz  May 8, 2024  Posted in Mix

GitLab - GitLab-Runner on Windows `DOCKER_AUTH_CONFIG` container host Command Injection

HackerOne bug report to GitLab: GitLab-Runner, when running on Windows with a docker executor, is vulnerable to Command Injection via the DOCKER_AUTH_CONFIG build variable. Injected commands are executed on the container host, not within a Docker container, as such could compromise all future builds which are executed by the runner.



Source link

Post navigation

LockBit gang claimed responsibility for the attack on City of Wichita →
← IntelBroker Hacker Claims Breach of Top Cybersecurity Firm, Selling Access

Latest Posts

  • Still on Windows 10? Enroll in free ESU before next week’s Patch Tuesday
  • GlassWorm malware returns on OpenVSX with 3 new VSCode extensions
  • OpenAI plans to release GPT-5.1, GPT-5.1 Reasoning, and GPT-5.1 Pro
  • China-linked hackers target U.S. non-profit in long-term espionage campaign
  • A new Italian citizen was targeted with Paragon’s Graphite spyware. We have a serious problem

Copyright © 2025 Cybernoz - Cybersecurity News

Design by ThemesDNA.com