GitLab secrets exposed as attackers move within 24 hours
Daily Cyber News: GitLab secrets exposed as attackers move within 24 hours
Secrets stored on self-hosted GitLab servers may already be exposed because attackers began exploiting a file-read weakness within 24 hours of disclosure. A single unauthenticated request can reveal S S H keys, database credentials, deploy tokens, CI/CD variables, and other configuration data. Affected versions include 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.
Key context: Public-facing instances face the highest immediate risk, but the impact may not stop at GitLab.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, GitLab, secrets, exposed, attackers, move, within, hours.