Saturday, January 11, 2025
HomeCVE/vulnerabilityGitLab Security Update, Patch for Critical Vulnerabilities

GitLab Security Update, Patch for Critical Vulnerabilities

Published on

GitLab announced the release of critical security patches for its Community Edition (CE) and Enterprise Edition (EE).

The newly released versions 17.6.2, 17.5.4, and 17.4.6 address several high-severity vulnerabilities, and GitLab strongly recommends that all self-managed installations be upgraded immediately.

It is worth noting that GitLab.com is already running the patched version, while GitLab-dedicated customers do not need to take any action.

GitLab employs a dual approach to patch releases, offering scheduled updates twice a month, alongside ad-hoc patches for critical issues.

The company emphasizes the importance of maintaining the highest security standards for all aspects of GitLab’s software, especially those handling customer data.

By upgrading to the latest patch releases, users can ensure optimal security for their GitLab instances.

2024 MITRE ATT&CK Evaluation Results for SMEs & MSPs -> Download Free Guide

Injection of Network Error Logging (NEL) Headers – CVE-2024-11274

One of the critical issues addressed in the new updates is the injection of Network Error Logging (NEL) headers in Kubernetes proxy responses.

This vulnerability affects all versions of GitLab CE/EE from 16.1 to 17.4.6, 17.5 to 17.5.4, and 17.6 to 17.6.2. Identified as CVE-2024-11274, this vulnerability could lead to session data exfiltration by abusing OAuth flows, posing a significant security risk.

The issue has been resolved in the latest release, and GitLab attributes the discovery of this vulnerability to a report by “joaxcar” via their HackerOne bug bounty program.

Denial of Service via Unauthenticated Requests – CVE-2024-8233

Another serious vulnerability addressed is a Denial of Service (DoS) attack vector that could be exploited by sending unauthenticated requests for diff files on a commit or merge request.

This vulnerability impacts all versions of GitLab CE/EE from 9.4 to 17.4.6, 17.5 to 17.5.4, and 17.6 to 17.6.2. Designated as CVE-2024-8233, this issue could allow an attacker to disrupt services significantly. It has now been mitigated in the latest patch release.

GitLab’s commitment to security is underscored by its transparent approach to handling vulnerabilities.

The company publishes detailed information about vulnerabilities on its issue tracker 30 days post-patch, allowing users to stay informed and secure.

For those seeking to bolster their GitLab environment’s security, GitLab provides additional resources and best practices through its blog.

GitLab’s latest patch release addresses critical security flaws, and users are urged to upgrade as soon as possible to ensure system integrity.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

QSC: Multi-Plugin Malware Framework Installs Backdoor on Windows

The QSC Loader service DLL named "loader.dll" leverages two distinct methods to obtain the...

Weaponized LDAP Exploit Deploys Information-Stealing Malware

Cybercriminals are exploiting the recent critical LDAP vulnerabilities (CVE-2024-49112 and CVE-2024-49113) by distributing fake...

New NonEuclid RAT Evades Antivirus and Encrypts Critical Files

A NonEuclid sophisticated C# Remote Access Trojan (RAT) designed for the.NET Framework 4.8 has...

Hackers Targeting Users Who Lodged Complaints On Government portal To Steal Credit Card Data

Fraudsters in the Middle East are exploiting a vulnerability in the government services portal....

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

QSC: Multi-Plugin Malware Framework Installs Backdoor on Windows

The QSC Loader service DLL named "loader.dll" leverages two distinct methods to obtain the...

Weaponized LDAP Exploit Deploys Information-Stealing Malware

Cybercriminals are exploiting the recent critical LDAP vulnerabilities (CVE-2024-49112 and CVE-2024-49113) by distributing fake...

New NonEuclid RAT Evades Antivirus and Encrypts Critical Files

A NonEuclid sophisticated C# Remote Access Trojan (RAT) designed for the.NET Framework 4.8 has...