DEV Community

Cover image for GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser

Summary

GitLab patched a critical remote code execution chain involving two memory corruption flaws in the Oj Ruby JSON parser that allow authenticated users to take over servers via malicious Jupyter notebook diffs.

Take Action:

If you run self-managed GitLab, upgrade immediately to version 18.10.8, 18.11.5, or 19.0.2. There's a working exploit published and any user who can push code to a project can take over the server. If you're on version 15.2 through 18.9, those are no longer supported and won't get a patch, so you must move to a supported release to be protected.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)