GitLab Vulnerability Exploited One Day After Disclosure

A critical-severity path traversal flaw in GitLab allows unauthenticated attackers to read arbitrary files from the server.

Bottom line: Security teams must prioritize patching this vulnerability immediately to prevent data breaches.

What's happening: A hacker exploited the vulnerability in the GitLab server, located in San Francisco, California, on August 18, 2022, just one day after its public disclosure by GitLab's security team on August 17, 2022. The vulnerability, identified as CVE-2022-29463, has a CVSS score of 9.8. A total of 1,045 commits were made to the GitLab repository before the vulnerability was disclosed.

What to do: Security teams should patch the GitLab server by applying the patch to the 14.9.0 version of GitLab, released on August 17, 2022, to prevent further exploitation.

Source: SecurityWeek