Active GitLab Attacks Put Source Code and Secrets at Risk
Daily Cyber News: Active GitLab Attacks Put Source Code and Secrets at Risk
Self-managed GitLab servers are under active attack through a weakness that can expose sensitive files without an account or any user interaction. CISA added the issue to its priority catalog on September 11th. The affected releases include versions 18.7 through 19.1.7, 19.2 through 19.2.5 and 19.3 through 19.3.1.
Key context: Successful exploitation could reveal source code, access tokens, deployment scripts, configuration data and other secrets stored on the server.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, Active GitLab Attacks Put Source Code, Active, GitLab, Attacks, Source, Code, Secrets.