GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations

A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve remote code execution on default GitLab installations, exposing source code, Rails secrets, and internal services. As part of the Open Defense Initiative, Depthfirst researcher Yuhang Wu used the automated analysis […]

The post GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: