GitLab Critical Security Release: 16.3.4 and 16.2.7

Discussion in 'other security issues & news' started by FanJ, Sep 19, 2023.

  1. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,953
    https://about.gitlab.com/releases/2023/09/18/security-release-gitlab-16-3-4-released/
    Sep 18, 2023 - Nick Malcolm

    Quoting:

    Learn more about GitLab Critical Security Release: 16.3.4 and 16.2.7 for GitLab Community Edition (CE) and Enterprise Edition (EE).

    These versions contain important security fixes, and we strongly recommend that all GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version.

    ...

    We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possible. For versions prior to 16.2, see the mitigations offered below.

    ...

    Attacker can abuse scan execution policies to run pipelines as another user
    Severity : Critical

    - end quotes -

    Read there more !!
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.