Start your day with intelligence. Get The OODA Daily Pulse.
GitLab updates fix XSS flaws and data‑exposure risks across CE and EE.
GitLab patched 13 vulnerabilities, including an EE XSS bug that let developers run client‑side code in other users’ sessions and a Web IDE XSS that allowed unauthenticated JavaScript execution. Another high‑severity flaw in Duo Workflows exposed committed sensitive information. Seven medium‑severity issues were also fixed, covering authorization bypass, improper filtering, and access‑control weaknesses. The patches ship in versions 19.1.1, 19.0.3, and 18.11.6, and GitLab urges immediate upgrades.
Read more:
https://www.securityweek.com/gitlab-patches-code-execution-information-disclosure-vulnerabilities/