News

GitLab Patches Critical Vulnerability

gitlab

GitLab has released a security update to address a critical vulnerability that may lead to remote code execution.

The vulnerability is tracked as CVE-2022-2884 and may allow an authenticated user to achieve remote code execution via the “Import from GitHub API” endpoint, as per an advisory from GitLab.

GitLab Urges Users to Update

It has since been patched, as GitLab urges all users to update to the latest version.

“These versions contain important security fixes, and we strongly recommend that all GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version,” the blog post reads.

Version 15.3 also contains a number of usability and UI improvements as well as more complex password requirements for GitLab accounts.