• doeknius_gloek@discuss.tchncs.de
    link
    fedilink
    arrow-up
    0
    ·
    9 months ago

    This patch is a week old, so hopefully you have already updated.

    GitLab seems to have glaring security holes quite often. Surely this is in part because of the open source codebase and their bug bounty program, which incentivizes researchers to look for these flaws. I’m still baffled sometimes. I’ve read about a lot of > 9.0 CVEs while maintaining our GitLab instance, there was a 10 only three weeks ago. Thankfully our instance isn’t public.