* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, October 26, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Meet Belynda From ‘Married at First Sight’ Season 19: Age, Job, Instagram and More – Yahoo

    Meet Belynda from ‘Married at First Sight’ Season 19: Age, Career, Instagram & More Revealed!

    General Hospital’s Rena Sofer Exits as Lois — But the Door Isn’t Closed – Yahoo

    General Hospital’s Rena Sofer Exits as Lois — But the Door Isn’t Closed – Yahoo

    CNN Launches New Show – What to Know About Host Elex Michaelson – Central Oregon Daily

    Get to Know Elex Michaelson: The Dynamic New Host Taking CNN by Storm

    Johnny Depp Set To Finally Make His Big Hollywood Comeback After Amber Heard Controversy – Yahoo

    Johnny Depp Set for a Triumphant Hollywood Comeback Following Amber Heard Controversy

    ‘Chainsaw Man — The Movie: Reze Arc’ Review: Hit Manga Gets an Ultra-Violent, Surprisingly Emotional Big-Screen Adaptation – Yahoo

    Chainsaw Man – The Movie: Reze Arc Review: A Brutal and Unexpectedly Emotional Big-Screen Adaptation

    Reba McEntire Details Personal Relationship With Late Stepson Brandon Blackstock – KNDU

    Reba McEntire Shares Emotional Tribute to Her Late Stepson Brandon Blackstock

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    The Anti-Tech Backlash Is Going to Grow Stronger – Jacobin

    The Anti-Tech Backlash Is Gaining Unstoppable Momentum

    Comments to EU Regarding the Draft Revised Technology Transfer Block Exemption Regulation and Technology Transfer Guidelines – Information Technology and Innovation Foundation

    Have Your Say: Share Your Thoughts on the Draft Revised Technology Transfer Block Exemption Regulation and Guidelines

    Ghost Tapping is exploiting tap-to-pay technology in order to steal your money; what your need to know – ABC7 New York

    Ghost Tapping: How Thieves Are Using Tap-to-Pay Technology to Steal Your Money and What You Need to Know

    New technology for grading and packing dates – FreshPlaza

    Revolutionary Technology Transforms Date Grading and Packing Process

    Project underway to upgrade technology on 911 towers in Kanawha County – WCHS

    Kanawha County Launches Major Upgrade to 911 Tower Technology

    Next steps: Technology opens new options for greater mobility – Missouri Independent

    Next Steps: How Technology is Opening Exciting New Doors to Greater Mobility

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Meet Belynda From ‘Married at First Sight’ Season 19: Age, Job, Instagram and More – Yahoo

    Meet Belynda from ‘Married at First Sight’ Season 19: Age, Career, Instagram & More Revealed!

    General Hospital’s Rena Sofer Exits as Lois — But the Door Isn’t Closed – Yahoo

    General Hospital’s Rena Sofer Exits as Lois — But the Door Isn’t Closed – Yahoo

    CNN Launches New Show – What to Know About Host Elex Michaelson – Central Oregon Daily

    Get to Know Elex Michaelson: The Dynamic New Host Taking CNN by Storm

    Johnny Depp Set To Finally Make His Big Hollywood Comeback After Amber Heard Controversy – Yahoo

    Johnny Depp Set for a Triumphant Hollywood Comeback Following Amber Heard Controversy

    ‘Chainsaw Man — The Movie: Reze Arc’ Review: Hit Manga Gets an Ultra-Violent, Surprisingly Emotional Big-Screen Adaptation – Yahoo

    Chainsaw Man – The Movie: Reze Arc Review: A Brutal and Unexpectedly Emotional Big-Screen Adaptation

    Reba McEntire Details Personal Relationship With Late Stepson Brandon Blackstock – KNDU

    Reba McEntire Shares Emotional Tribute to Her Late Stepson Brandon Blackstock

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    The Anti-Tech Backlash Is Going to Grow Stronger – Jacobin

    The Anti-Tech Backlash Is Gaining Unstoppable Momentum

    Comments to EU Regarding the Draft Revised Technology Transfer Block Exemption Regulation and Technology Transfer Guidelines – Information Technology and Innovation Foundation

    Have Your Say: Share Your Thoughts on the Draft Revised Technology Transfer Block Exemption Regulation and Guidelines

    Ghost Tapping is exploiting tap-to-pay technology in order to steal your money; what your need to know – ABC7 New York

    Ghost Tapping: How Thieves Are Using Tap-to-Pay Technology to Steal Your Money and What You Need to Know

    New technology for grading and packing dates – FreshPlaza

    Revolutionary Technology Transforms Date Grading and Packing Process

    Project underway to upgrade technology on 911 towers in Kanawha County – WCHS

    Kanawha County Launches Major Upgrade to 911 Tower Technology

    Next steps: Technology opens new options for greater mobility – Missouri Independent

    Next Steps: How Technology is Opening Exciting New Doors to Greater Mobility

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

GitLab: Critical bug lets attackers run pipelines as other users

July 11, 2024
in Technology
GitLab: Critical bug lets attackers run pipelines as other users
Share on FacebookShare on Twitter

GitLab

GitLab warned today that a critical vulnerability in its product’s GitLab Community and Enterprise editions allows attackers to run pipeline jobs as any other user.

The GitLab DevSecOps platform has over 30 million registered users and is used by over 50% of Fortune 100 companies, including T-Mobile, Goldman Sachs, Airbus, Lockheed Martin, Nvidia, and UBS.

The flaw patched in today’s security update is tracked as CVE-2024-6385, and it received a CVSS base score severity rating of 9.6 out of 10.

It impacts all GitLab CE/EE versions from 15.8 to 16.11.6, 17.0 to 17.0.4, and 17.1 to 17.1.2. Under certain circumstances that GitLab has yet to disclose, attackers can exploit it to trigger a new pipeline as an arbitrary user.

GitLab pipelines are a Continuous Integration/Continuous Deployment (CI/CD) system feature that lets users automatically run processes and tasks in parallel or sequentially to build, test, or deploy code changes.

The company released GitLab Community and Enterprise versions 17.1.2, 17.0.4, and 16.11.6 to address this critical security flaw and advised all admins to upgrade all installations immediately.

“We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possible,” it warned. “GitLab.com and GitLab Dedicated are already running the patched version.”

Account takeover flaw actively exploited in attacks

GitLab patched an almost identical vulnerability (tracked as CVE-2024-5655) in late June, which could also be exploited to run pipelines as other users.

One month earlier, it fixed a high-severity vulnerability (CVE-2024-4835) that enables unauthenticated threat actors to take over accounts in cross-site scripting (XSS) attacks.

As CISA warned in May, threat actors are also actively exploiting another zero-click GitLab vulnerability (CVE-2023-7028) patched in January. This vulnerability allows unauthenticated attackers to hijack accounts via password resets.

While Shadowserver found over 5,300 vulnerable GitLab instances exposed online in January, less than half (1,795) are still reachable today.

Attackers target GitLab because it hosts various types of sensitive corporate data, including API keys and proprietary code, leading to significant security impact following a breach.

This includes supply chain attacks if the threat actors insert malicious code in CI/CD (Continuous Integration/Continuous Deployment) environments, compromising the breached organization’s repositories.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-bug-that-lets-attackers-run-pipelines-as-an-arbitrary-user/

Tags: criticalGitLabtechnology
Previous Post

ViperSoftX malware covertly runs PowerShell using AutoIT scripting

Next Post

Huione Guarantee exposed as a $11 billion marketplace for cybercrime

Seismic evidence for a highly heterogeneous martian mantle – Science | AAAS

October 26, 2025
Neanderthals could be brought back within 20 years — but is it a good idea? – Live Science

Could Neanderthals Walk the Earth Again in 20 Years? Unveiling the Exciting Possibilities and Risks of De-Extinction

October 26, 2025
Former L3Harris cyber director charged with selling secrets – theregister.com

Former L3Harris cyber director charged with selling secrets – theregister.com

October 26, 2025
The Anti-Tech Backlash Is Going to Grow Stronger – Jacobin

The Anti-Tech Backlash Is Gaining Unstoppable Momentum

October 26, 2025
‘Not Enough Adjectives’: How Yoshinobu Yamamoto Amazed His Dodgers Teammates – FOX Sports

Not Enough Adjectives’: How Yoshinobu Yamamoto Amazed His Dodgers Teammates

October 26, 2025
World Series 2025: Dodgers’ worst-case scenario plays out as Blake Snell, bullpen crumble in Game 1 vs. Blue Jays: ‘Not a good feeling’ – Yahoo Sports

World Series 2025: Dodgers’ Nightmare Unfolds as Blake Snell and Bullpen Collapse in Game 1 vs. Blue Jays

October 26, 2025
“Bending, not breaking”: The global economy’s new normal – J.P. Morgan

Bending, Not Breaking: Embracing the New Normal of the Global Economy

October 26, 2025
Meet Belynda From ‘Married at First Sight’ Season 19: Age, Job, Instagram and More – Yahoo

Meet Belynda from ‘Married at First Sight’ Season 19: Age, Career, Instagram & More Revealed!

October 26, 2025
80,000 Coloradans projected to drop health insurance amid premium spike – KUSA.com

80,000 Coloradans Expected to Lose Health Insurance as Premiums Soar

October 26, 2025
Trump departs for Asia where he will meet with China’s Xi. Here’s what else to expect – PBS

Trump departs for Asia where he will meet with China’s Xi. Here’s what else to expect – PBS

October 26, 2025

Categories

Archives

October 2025
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Sep    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (886)
  • Economy (908)
  • Entertainment (21,779)
  • General (17,811)
  • Health (9,949)
  • Lifestyle (921)
  • News (22,149)
  • People (909)
  • Politics (918)
  • Science (16,119)
  • Sports (21,408)
  • Technology (15,888)
  • World (891)

Recent News

Seismic evidence for a highly heterogeneous martian mantle – Science | AAAS

October 26, 2025
Neanderthals could be brought back within 20 years — but is it a good idea? – Live Science

Could Neanderthals Walk the Earth Again in 20 Years? Unveiling the Exciting Possibilities and Risks of De-Extinction

October 26, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version