@beyondmachines1@infosec.exchange
Post #4160481
2026-07-28 10:01 UTC
GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser
GitLab patched a critical remote code execution chain involving two memory corruption flaws in the Oj Ruby JSON parser that allow authenticated users to take over servers via malicious Jupyter notebook diffs.
**If you run self-managed GitLab, upgrade immediately to version 18.10.8, 18.11.5, or 19.0.2. There's a working exploit published and any user who can push code to a project can take over the server. If you're on version 15.2 through 18.9, those are no longer supported and won't get a patch, so you must move to a supported release to be protected.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/gitlab-remote-code-execution-chain-exploits-long-standing-memory-flaws-in-oj-parser-q-z-g-i-b/gD2P6Ple2L
Replies (0)
No replies.