A maximum-severity path traversal flaw in GitLab’s repository commits API is being scanned within hours of disclosure. Here’s what happened and what self-managed users need to check.
Tag:
GitLab
-
-
A critical GitLab GraphQL vulnerability let unauthenticated attackers delete public repositories, and researchers saw real exploitation attempts within two days of the patch shipping.