GitLab CE/EE 是由 GitLab 公司开发的、基于 Git 的集成软件开发平台。 GitLab CE/EE 的受影响版本中存在敏感信息泄露漏洞,经过身份验证的攻击者(如维护人员)可以通过修改集成 URL,将经过身份验证的请求发送到攻击者控制的服务器,从而获取 GitHub 集成的访问令牌。
A maximum severity vulnerability that allows hackers to hijack GitLab accounts with no user interaction required is now under active exploitation, federal government ...
GitLab has released security updates to address a critical SAML authentication bypass vulnerability impacting self-managed installations of the GitLab Community Edition (CE) and Enterprise Edition (EE ...