Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Gitlab Critical Security Release: 16.7.2, 16.6.4, 16.5.6 (about.gitlab.com)
4 points by batch12 on Jan 12, 2024 | hide | past | favorite | 1 comment


Didn't get much notice from my post of it: https://news.ycombinator.com/item?id=38961910

The POC is quite trivial for it:

user[email][]=valid@email.com&user[email][]=attacker@email.com

It was severe enough that paid customers got a heads up to be ready to patch.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: