* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Saturday, December 27, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Holiday light displays, ice hockey and more things to do this week: Around Baton Rouge – The Advocate

    Brighten Your Week in Baton Rouge: Holiday Light Displays, Ice Hockey, and More Exciting Events

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    The big business stories in Hollywood with entertainment reporter John Horn – NEPM

    Unveiling Hollywood’s Biggest Business Stories with Entertainment Reporter John Horn

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

    Las Vegas: Caesars Entertainment extending discounts into 2026 – CDC Gaming

    Las Vegas: Caesars Entertainment extending discounts into 2026 – CDC Gaming

    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Tool Developed at Montana State Aims to Help Farmers Implement New Technologies – Northern Ag Network

    Montana State Unveils Innovative Tool That Empowers Farmers to Harness Cutting-Edge Technologies

    Micron Technology (MU) Stock News and Forecasts: Record Highs, HBM Demand, and Analyst Targets to Watch on Dec. 26, 2025 – ts2.tech

    Micron Technology Hits Record Highs: Unpacking the Surge in HBM Demand and Key Analyst Targets for December 26, 2025

    Mehai Technology Limited (540730)’s Trend in 2025 – Market Entry Points & Low Risk Trading Plans – Bollywood Helpline

    Mehai Technology Limited (540730) in 2025: Unlocking Key Market Entry Points and Low-Risk Trading Strategies

    [News] Japan Develops 10nm Nanoimprint Technology, with Potential to Tackle EUV Bottleneck – TrendForce

    Japan Unveils Revolutionary 10nm Nanoimprint Technology Set to Surpass EUV Constraints

    Rising technology use prompts digital detoxing efforts in Austin – Community Impact | News

    Austin Embraces a Growing Digital Detox Movement Amid Tech Surge

    Astrobotic Technology lands $17.5M in contracts to advance reusable rocket development – WPXI

    Astrobotic Technology Lands $17.5M to Drive Breakthroughs in Reusable Rocket Innovation

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Holiday light displays, ice hockey and more things to do this week: Around Baton Rouge – The Advocate

    Brighten Your Week in Baton Rouge: Holiday Light Displays, Ice Hockey, and More Exciting Events

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    City of Gautier signs off on entertainment contract extension for The Sound Amphitheater – WLOX

    The big business stories in Hollywood with entertainment reporter John Horn – NEPM

    Unveiling Hollywood’s Biggest Business Stories with Entertainment Reporter John Horn

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

    Bart Story Dies: Veteran Entertainment Research Executive Was 63 – Deadline

    Las Vegas: Caesars Entertainment extending discounts into 2026 – CDC Gaming

    Las Vegas: Caesars Entertainment extending discounts into 2026 – CDC Gaming

    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

    Ayushmann Khurrana Banks on Family Entertainment With Four-Film Slate Following ‘Thamma’ Success (EXCLUSIVE) – Variety

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Tool Developed at Montana State Aims to Help Farmers Implement New Technologies – Northern Ag Network

    Montana State Unveils Innovative Tool That Empowers Farmers to Harness Cutting-Edge Technologies

    Micron Technology (MU) Stock News and Forecasts: Record Highs, HBM Demand, and Analyst Targets to Watch on Dec. 26, 2025 – ts2.tech

    Micron Technology Hits Record Highs: Unpacking the Surge in HBM Demand and Key Analyst Targets for December 26, 2025

    Mehai Technology Limited (540730)’s Trend in 2025 – Market Entry Points & Low Risk Trading Plans – Bollywood Helpline

    Mehai Technology Limited (540730) in 2025: Unlocking Key Market Entry Points and Low-Risk Trading Strategies

    [News] Japan Develops 10nm Nanoimprint Technology, with Potential to Tackle EUV Bottleneck – TrendForce

    Japan Unveils Revolutionary 10nm Nanoimprint Technology Set to Surpass EUV Constraints

    Rising technology use prompts digital detoxing efforts in Austin – Community Impact | News

    Austin Embraces a Growing Digital Detox Movement Amid Tech Surge

    Astrobotic Technology lands $17.5M in contracts to advance reusable rocket development – WPXI

    Astrobotic Technology Lands $17.5M to Drive Breakthroughs in Reusable Rocket Innovation

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

GitLab: Critical bug lets attackers run pipelines as other users

July 11, 2024
in Technology
GitLab: Critical bug lets attackers run pipelines as other users
Share on FacebookShare on Twitter

GitLab

GitLab warned today that a critical vulnerability in its product’s GitLab Community and Enterprise editions allows attackers to run pipeline jobs as any other user.

The GitLab DevSecOps platform has over 30 million registered users and is used by over 50% of Fortune 100 companies, including T-Mobile, Goldman Sachs, Airbus, Lockheed Martin, Nvidia, and UBS.

The flaw patched in today’s security update is tracked as CVE-2024-6385, and it received a CVSS base score severity rating of 9.6 out of 10.

It impacts all GitLab CE/EE versions from 15.8 to 16.11.6, 17.0 to 17.0.4, and 17.1 to 17.1.2. Under certain circumstances that GitLab has yet to disclose, attackers can exploit it to trigger a new pipeline as an arbitrary user.

GitLab pipelines are a Continuous Integration/Continuous Deployment (CI/CD) system feature that lets users automatically run processes and tasks in parallel or sequentially to build, test, or deploy code changes.

The company released GitLab Community and Enterprise versions 17.1.2, 17.0.4, and 16.11.6 to address this critical security flaw and advised all admins to upgrade all installations immediately.

“We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possible,” it warned. “GitLab.com and GitLab Dedicated are already running the patched version.”

Account takeover flaw actively exploited in attacks

GitLab patched an almost identical vulnerability (tracked as CVE-2024-5655) in late June, which could also be exploited to run pipelines as other users.

One month earlier, it fixed a high-severity vulnerability (CVE-2024-4835) that enables unauthenticated threat actors to take over accounts in cross-site scripting (XSS) attacks.

As CISA warned in May, threat actors are also actively exploiting another zero-click GitLab vulnerability (CVE-2023-7028) patched in January. This vulnerability allows unauthenticated attackers to hijack accounts via password resets.

While Shadowserver found over 5,300 vulnerable GitLab instances exposed online in January, less than half (1,795) are still reachable today.

Attackers target GitLab because it hosts various types of sensitive corporate data, including API keys and proprietary code, leading to significant security impact following a breach.

This includes supply chain attacks if the threat actors insert malicious code in CI/CD (Continuous Integration/Continuous Deployment) environments, compromising the breached organization’s repositories.

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : BleepingComputer – https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-bug-that-lets-attackers-run-pipelines-as-an-arbitrary-user/

Tags: criticalGitLabtechnology
Previous Post

ViperSoftX malware covertly runs PowerShell using AutoIT scripting

Next Post

Huione Guarantee exposed as a $11 billion marketplace for cybercrime

Ecological myopia: the blind spot holding back climate action – The Conversation

Ecological Myopia: The Overlooked Barrier Blocking Real Climate Progress

December 27, 2025
Uranus and Neptune may be ‘rock giants,’ not ‘ice giants,’ new model of their cores suggests – Live Science

Uranus and Neptune May Be ‘Rock Giants’ Rather Than ‘Ice Giants,’ New Core Model Suggests

December 27, 2025
Our 7 Best Science TikToks You Need to Watch Right Now – Scientific American

7 Mind-Blowing Science TikToks You Absolutely Can’t Miss

December 27, 2025
Speciesism: the bias you never knew you had – VegOut

Uncovering Speciesism: The Surprising Bias Hiding in Plain Sight

December 27, 2025
Tool Developed at Montana State Aims to Help Farmers Implement New Technologies – Northern Ag Network

Montana State Unveils Innovative Tool That Empowers Farmers to Harness Cutting-Edge Technologies

December 27, 2025
Atlanta TV sports listings – AJC.com

Atlanta TV sports listings – AJC.com

December 27, 2025
‘I had all the faith in the world’: Vietnam veteran Billy Cockerel celebrates 12 years of life after life-saving procedure – WHAS11

Vietnam Veteran Billy Cockerel Celebrates 12 Years of Life After Miraculous Procedure

December 26, 2025
Trump’s economy pitch rankles Senate GOP – The Hill

Trump’s Economic Pitch Ignites Frustration Among Senate Republicans

December 26, 2025
Holiday light displays, ice hockey and more things to do this week: Around Baton Rouge – The Advocate

Brighten Your Week in Baton Rouge: Holiday Light Displays, Ice Hockey, and More Exciting Events

December 26, 2025
Researchers awarded Iowa Livestock Health Advisory Council grants – National Hog Farmer

Innovative Grants Propel Advancements in Iowa Livestock Health and Animal Care

December 26, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (990)
  • Economy (1,008)
  • Entertainment (21,885)
  • General (18,975)
  • Health (10,048)
  • Lifestyle (1,021)
  • News (22,149)
  • People (1,015)
  • Politics (1,022)
  • Science (16,224)
  • Sports (21,509)
  • Technology (15,991)
  • World (997)

Recent News

Ecological myopia: the blind spot holding back climate action – The Conversation

Ecological Myopia: The Overlooked Barrier Blocking Real Climate Progress

December 27, 2025
Uranus and Neptune may be ‘rock giants,’ not ‘ice giants,’ new model of their cores suggests – Live Science

Uranus and Neptune May Be ‘Rock Giants’ Rather Than ‘Ice Giants,’ New Core Model Suggests

December 27, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version