* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, June 21, 2026
Earth-News
  • Home
  • Business
  • Entertainment

    Olandria Carthen’s Platform Goes Global: Redefining Influence Beyond Entertainment

    Why Jamie Lynn Spears Embraced a Quiet Life Away from Hollywood to Raise Her Daughter

    Henry Winkler says Ron Howard was ‘almost vomiting’ when Happy Days made this huge change – Entertainment Weekly

    IDW Dark Comics Score Big with Sports Drama in ‘Smile’ and Chilling Horror in the Florida Keys with ‘A Quiet Place

    Beloved Retro Jim Henson Characters Star in an Exciting New Show Coming to Harrisburg

    JUST IN: Tucker Wetmore Inks With Sandbox Entertainment – MusicRow.com

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Nevada Schools Innovate to Overcome Screen Time Challenges in Modern Classrooms

    QuintoAndar to Invest R$2 Billion in Cutting-Edge AI Technology by 2028

    Durst Group Celebrates 90 Years of Innovation with Thrilling Durst NEXT Technology Festival in Brixen

    License Plate Reader Technology Breaks Open Auburn Shooting Case with Key Arrest

    Cohere Broadens Its Reach with Acquisition of Reliant AI to Launch Groundbreaking Sovereign Biopharma Platform

    How Satellite Technology Is Transforming the Future of Global Drinking Water Protection

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment

    Olandria Carthen’s Platform Goes Global: Redefining Influence Beyond Entertainment

    Why Jamie Lynn Spears Embraced a Quiet Life Away from Hollywood to Raise Her Daughter

    Henry Winkler says Ron Howard was ‘almost vomiting’ when Happy Days made this huge change – Entertainment Weekly

    IDW Dark Comics Score Big with Sports Drama in ‘Smile’ and Chilling Horror in the Florida Keys with ‘A Quiet Place

    Beloved Retro Jim Henson Characters Star in an Exciting New Show Coming to Harrisburg

    JUST IN: Tucker Wetmore Inks With Sandbox Entertainment – MusicRow.com

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology

    Nevada Schools Innovate to Overcome Screen Time Challenges in Modern Classrooms

    QuintoAndar to Invest R$2 Billion in Cutting-Edge AI Technology by 2028

    Durst Group Celebrates 90 Years of Innovation with Thrilling Durst NEXT Technology Festival in Brixen

    License Plate Reader Technology Breaks Open Auburn Shooting Case with Key Arrest

    Cohere Broadens Its Reach with Acquisition of Reliant AI to Launch Groundbreaking Sovereign Biopharma Platform

    How Satellite Technology Is Transforming the Future of Global Drinking Water Protection

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

GitLab: Critical bug lets attackers run pipelines as other users

July 11, 2024
in Technology
GitLab: Critical bug lets attackers run pipelines as other users
Share on FacebookShare on Twitter

GitLab

GitLab warned today that a critical vulnerability in its product’s GitLab Community and Enterprise editions allows attackers to run pipeline jobs as any other user.

The GitLab DevSecOps platform has over 30 million registered users and is used by over 50% of Fortune 100 companies, including T-Mobile, Goldman Sachs, Airbus, Lockheed Martin, Nvidia, and UBS.

The flaw patched in today’s security update is tracked as CVE-2024-6385, and it received a CVSS base score severity rating of 9.6 out of 10.

It impacts all GitLab CE/EE versions from 15.8 to 16.11.6, 17.0 to 17.0.4, and 17.1 to 17.1.2. Under certain circumstances that GitLab has yet to disclose, attackers can exploit it to trigger a new pipeline as an arbitrary user.

GitLab pipelines are a Continuous Integration/Continuous Deployment (CI/CD) system feature that lets users automatically run processes and tasks in parallel or sequentially to build, test, or deploy code changes.

The company released GitLab Community and Enterprise versions 17.1.2, 17.0.4, and 16.11.6 to address this critical security flaw and advised all admins to upgrade all installations immediately.

“We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possible,” it warned. “GitLab.com and GitLab Dedicated are already running the patched version.”

Account takeover flaw actively exploited in attacks

GitLab patched an almost identical vulnerability (tracked as CVE-2024-5655) in late June, which could also be exploited to run pipelines as other users.

One month earlier, it fixed a high-severity vulnerability (CVE-2024-4835) that enables unauthenticated threat actors to take over accounts in cross-site scripting (XSS) attacks.

As CISA warned in May, threat actors are also actively exploiting another zero-click GitLab vulnerability (CVE-2023-7028) patched in January. This vulnerability allows unauthenticated attackers to hijack accounts via password resets.

While Shadowserver found over 5,300 vulnerable GitLab instances exposed online in January, less than half (1,795) are still reachable today.

Attackers target GitLab because it hosts various types of sensitive corporate data, including API keys and proprietary code, leading to significant security impact following a breach.

This includes supply chain attacks if the threat actors insert malicious code in CI/CD (Continuous Integration/Continuous Deployment) environments, compromising the breached organization’s repositories.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-bug-that-lets-attackers-run-pipelines-as-an-arbitrary-user/

Tags: criticalGitLabtechnology
Previous Post

ViperSoftX malware covertly runs PowerShell using AutoIT scripting

Next Post

Huione Guarantee exposed as a $11 billion marketplace for cybercrime

Gavin Newsom’s Bright Vision for California’s Economy Overlooks Its Hidden Challenges

June 21, 2026

How One Provider Transformed Care by Slashing Antipsychotic Use, Behavioral Issues, and Hospitalizations with SNF Mental Health Assistants

June 21, 2026

Olandria Carthen’s Platform Goes Global: Redefining Influence Beyond Entertainment

June 21, 2026

Jordan Wright Gears Up for Intense Showdown in 70th Assembly District Primary

June 21, 2026

Nevada Schools Innovate to Overcome Screen Time Challenges in Modern Classrooms

June 20, 2026

How a Fierce Wildfire Nearly Destroyed a Pristine California Island-and the Epic Fight to Save Its Unique Ecosystem

June 20, 2026

Thrilling Showdown: San Diego Padres Clash with Texas Rangers

June 20, 2026

Scientists Reveal the Unexpected Secret Behind Why Mosquitoes Target Some People More Than Others

June 20, 2026

The Science Behind ‘Dad Brain’: How Fatherhood Transforms Men

June 20, 2026

Watters calls out Obama’s high-profile lifestyle after the White House – Fox News

June 20, 2026

Categories

Archives

June 2026
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
2930  
« May    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (1,276)
  • Economy (1,298)
  • Entertainment (22,175)
  • General (22,206)
  • Health (10,333)
  • Lifestyle (1,309)
  • News (22,149)
  • People (1,300)
  • Politics (1,318)
  • Science (16,511)
  • Sports (21,796)
  • Technology (16,283)
  • World (1,289)

Recent News

Gavin Newsom’s Bright Vision for California’s Economy Overlooks Its Hidden Challenges

June 21, 2026

How One Provider Transformed Care by Slashing Antipsychotic Use, Behavioral Issues, and Hospitalizations with SNF Mental Health Assistants

June 21, 2026
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version