As cited
Copy frozen at (site build).
vulnerabilities
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
A researcher released a working proof-of-concept exploit for an unpatched GitLab vulnerability (CVE-18.11.3) that allows authenticated users to execute arbitrary commands with git privileges. The attack requires only two malicious Jupyter notebook commits and a diff request, with no need for administrator rights or CI runner access.
Why it matters: Self-managed GitLab administrators must patch immediately; any authenticated user on an unpatched 18.11.3 instance can escalate to git-level command execution without additional privileges or user interaction.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
A researcher released a working proof-of-concept exploit for an unpatched GitLab vulnerability (CVE-18.11.3) that allows authenticated users to execute arbitrary commands with git privileges. The attack requires only two malicious Jupyter notebook commits and a diff request, with no need for administrator rights or CI runner access.
Why it matters: Self-managed GitLab administrators must patch immediately; any authenticated user on an unpatched 18.11.3 instance can escalate to git-level command execution without additional privileges or user interaction.
- Source published
- First seen by Cybersecurity Tracker