The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers at depthfirst published public exploit code on July 24 for a GitLab remote code execution flaw that was patched on June 10.
- Any authenticated user who can push to a project can run commands as the git user on unpatched self-managed servers by committing crafted Jupyter notebooks, without needing admin rights or victim interaction.
- The chain exploits two memory corruption bugs in the Oj Ruby JSON parser, but GitLab shipped the fix as a regular bug fix with no CVE, CVSS score, or security classification, so operators had no reason to treat the June release as urgent.
- There is no workaround for those who cannot upgrade, no confirmed in-the-wild exploitation, and GitLab has not yet answered questions about the missing security designation.
What to watch next
- Whether GitLab assigns a CVE and reclassifies the June 10 fix as a security issue
- Uptake of the fixed versions (18.10.8, 18.11.5, 19.0.2) and any sign of real-world exploitation now that exploit code is public
- Guidance from GitLab or the Oj maintainer for operators on unsupported releases or those unable to upgrade
Coverage1
1 report
English national1
All filed from India
Named India · GitLab · Oj · depthfirst · Yuhang Wu
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
