RESEARCH from Depthfirst highlights a critical remote code execution (RCE) vulnerability in GitLab, resulting from two memory corruption bugs in the Oj JSON parser. These vulnerabilities affect authenticated users who can push to projects and view commit diffs. The flaws, which remain unpatched for over five years, are exploited all the way through GitLab’s notebook diff renderer. GitLab has acknowledged the issue and released patches, advising users of versions 15.2.0 through 19.0.1 to upgrade accordingly. The exploit can lead to severe consequences, including source-code disclosure and credential theft.
GitLab patches RCE flaw in Oj JSON parser after five year wait
CyberSIXT Evidence Panel
Primary Source
depthfirst.com
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
GitLab patches RCE flaw in Oj JSON parser after five year wait
securityaffairs.com
-
GitLab flaw enables logged in users to run commands as Git user
thehackernews.com