HomeSecurityGitLab: Warns of critical vulnerability - Update immediately!

GitLab: Warns of critical vulnerability - Update immediately!

GitLab recommends that its users install a security update for the 15.1, 15.2, and 15.3 branches of the community and enterprise editions to fix a critical vulnerability that could put them at serious risk. This is a vulnerability that allows an attacker to execute commands remotely via Github import.

GitLab vulnerability

GitLab is an online Git repository for development teams that need to manage their code remotely. The service has about 30 million registered users and one million paying customers.

See also: AiTM attack targets Google G-Suite Enterprise users

GitLab releases patches for vulnerabilities in special security releases. There are two types of security releases: a monthly, scheduled security and ad-hoc releases for critical bugs.

The critical vulnerability affecting the software is tracked as CVE-2022-2884 and has a CVSS v3 severity rating of 9.9. It affects all versions from 11.3.4 to 15.1.4, those between 15.2 and 15.2.3 and 15.3. Therefore, it is essential to install the security update.

GitLab emphasizes that the deployment type (omnibus, source code, helm chart, etc.) makes no difference, as everything is affected.

GitLab: Vulnerability allows remote command execution

Remote command execution vulnerabilities are quite common and dangerous. A malicious user could exploit this vulnerability to execute malicious code on the target machine remotely, introduce malware and backdoors, or gain complete control of the vulnerable endpoint.

See also: Chrome's "Internet Download Manager" turned out to be adware

Using this vulnerability, an attacker could take control of the server, steal or delete source code, execute malicious commands, and more.

The latest GitLab versions affected are 15.3.1, 15.2.3, and 15.1.5. Users should upgrade immediately to stay safe.

“We strongly recommend that all installations running a version affected by the issues described below upgrade to the latest version as soon as possible,” GitLab’s announcement states.

GitLab update

What to do if the update cannot be installed?

If security updates cannot be installed for any reason, GitLab recommends implementing a temporary solution that involves disabling GitHub import, a tool used to import entire software projects from GitHub to GitLab.

See also: Plex.tv data leak. Change passwords immediately!

So if you can't install the security update immediately, apply this temporary solution by following these steps:

  • Log in using an administrator account on your GitLab installation.
  • Click on “Menu” -> “Admin”
  • Then, click on “Settings” -> “General”
  • Open the “Visibility and access controls”
  • In the “ Import sources ” section, disable the “ GitHub ” option
  • Finally, click on “Save changes” to save the changes you made.

To make sure you followed the procedure correctly and that the solution has been applied, follow these steps:

  • In a browser window, log in as any user.
  • Click on “+” on the top bar
  • Click on “New project/repository“
  • Click on “Import project“
  • Make sure “GitHub” is not listed as an import option.

If you can install the security update, do so immediately. For instructions on how to update your GitLab installation, go to the project's official updating portal .

Since the vulnerability, cybercriminals may already be looking for ways to exploit it. So hurry up if you want to stay safe!

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS