GitLab RCE 취약점에 대한 PoC가 공개되어 인증된 사용자가 명령을 실행할 수 있습니다.
안전 연구자들이 GitLab의 취약점을 이용한 원격 코드 실행(RCE) 익스플로잇 코드를 발표했습니다. 이 취약점은 6주 전 패치되지 않은 GitLab 18.11.3 버전에서 발생하며, 인증된 사용자가 프로젝트에 푸시 할 수 있는 경우 명령을 실행할 수 있습니다. 공격자는 취약한 Jupyter 노트북을 커밋하여 이를 통해 힙 정보를 유출할 수 있습니다.
A PoC for a GitLab RCE vulnerability lets authenticated users execute commands.
Security researchers have published an exploit code for a remote code execution (RCE) vulnerability in GitLab. This vulnerability affects unpatched self-managed GitLab version 18.11.3, allowing any authenticated user who can push to a project to execute commands. The attacker can leverage a crafted Jupyter notebook to leak heap information.