Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » GitLab fixes a critical bug that allows unauthorized pipeline jobs
Global Security

GitLab fixes a critical bug that allows unauthorized pipeline jobs

AdminBy AdminJuly 11, 2024No Comments3 Mins Read
Software Flaws
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


July 11, 2024Information hallSoftware Security / Vulnerability

Software flaws

GitLab has released another round of updates to address security flaws in its software development platform, including a critical bug that allows an attacker to run pipeline jobs as an arbitrary user.

Tracked as CVE-2024-6385, the vulnerability has a CVSS score of 9.6 out of a maximum of 10.0.

“An issue was discovered in GitLab CE/EE versions 15.8 through 16.11.6, 17.0 through 17.0.4, and 17.1 through 17.1.2 that could allow an attacker to run the pipeline from another user under certain circumstances,” the company said in consultation on Wednesday.

It should be noted that the company fixed a similar bug late last month (CVE-2024-5655CVSS score: 9.6) which can also be weapons to launch pipelines from other users.

Cyber ​​security

GitLab is also addressing a medium-severity issue (CVE-2024-5257, CVSS score: 4.9) that allows a developer user with admin_compliance_framework permissions to modify the URL for a group namespace.

All security vulnerabilities have been fixed in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 17.1.2, 17.0.4, and 16.11.6.

Disclosure is made as Citrix released Updates for a critical incorrect authentication flaw affecting NetScaler Console (formerly NetScaler ADM), NetScaler SDX, and NetScaler Agent (CVE-2024-6235, CVSS Score: 9.4) that could lead to information disclosure.

Broadcom also released patches for two medium-severity vulnerabilities in the VMware Cloud Director (CVE-2024-22277, CVSS score: 6.4) and VMware Aria Automation (CVE-2024-22280, CVSS Score: 8.5), which can be used to execute malicious code using specially crafted HTML tags and SQL queries, respectively.

CISA issues bulletins to address software flaws

These developments also follow a new bulletin issued by the US Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) urging technology manufacturers to address flaws in the implementation of operating system (OS) commands in software that allow threat actors to remotely execute code on network edge devices.

Such flaws occur when user input is not properly cleaned and validated when commands are designed to be executed in the underlying operating system, allowing an adversary to smuggle arbitrary commands that could lead to the deployment of malware or information theft.

“OS command injection vulnerabilities have long been preventable by clearly separating user input from command content,” the agencies note. said. “Despite this finding, OS command injection vulnerabilities—many of which are the result of CWE-78 — are still the predominant group of vulnerabilities.”

This is the third alert issued by CISA and the FBI since the beginning of the year. Earlier, the authorities sent out two more warnings about the need for liquidation SQL injection (SQLi) and path traversal vulnerabilities in March and May 2024.

Cyber ​​security

Last month, CISA, along with cyber security agencies from Canada and New Zealand, also issued guidance advising businesses to adopt more robust security solutions such as Zero trustSecure Service Edge (SSE), and Secure Access Service Edge (SIX) — which provide greater visibility into network activity.

“Using risk-based access control policies to make decisions through policy decision-making mechanisms, these solutions integrate security and access control, enhancing the usability and security of the organization through adaptive policies.” – author agencies noted.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025

Germany closes the exp.

May 10, 2025

Google pays $ 1.375 for unauthorized tracking and biometric data collection

May 10, 2025

Ottercookie V4 adds detection of VM and Chrome, Metamask Centive Chardenties

May 9, 2025

Breaking: 7000-Delicious Proxy using iol Systems Systems

May 9, 2025

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

ASUS PATCHES DRIVERHUB RCE DISTRUCTIONS OPERATED THROUGH HTTP AND CONTROL .INI FILE

May 12, 2025

Why the exposed powers remain units – and how to change

May 12, 2025

AI fake tools used to distribute malicious software with catching, focusing 62,000+ via lure on Facebook

May 12, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.