{"id":457949,"date":"2022-08-25T12:53:53","date_gmt":"2022-08-25T10:53:53","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=457949"},"modified":"2022-08-25T12:53:53","modified_gmt":"2022-08-25T10:53:53","slug":"gitlab-urges-users-to-patch-critical-vulnerability","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/457949-gitlab-urges-users-to-patch-critical-vulnerability.html","title":{"rendered":"GitLab urges users to patch critical vulnerability"},"content":{"rendered":"<p>GitLab wants users to urgently install an update for versions 15.1, 15.2, and 15.3 of its community and enterprise edition to address a flaw attackers could exploit to remotely execute commands via its GitHub import tool.<\/p>\n<p>The vulnerability is tracked as CVE-2022-2884 and has been assigned a Common Vulnerability Scoring System (CVSS) v3 of 9.9 out of 10.<\/p>\n<p>CVSS is an open framework for communicating the characteristics and severity of software vulnerabilities. A rating of 9.9 represents a critical security flaw.<\/p>\n<p>&#8220;Today we are releasing versions 15.3.1, 15.2.3, and 15.1.5 for GitLab Community Edition (CE) and Enterprise Edition (EE),&#8221; application security specialist at GitLab, Nick Malcolm, said in a <strong><a href=\"https:\/\/about.gitlab.com\/releases\/2022\/08\/22\/critical-security-release-gitlab-15-3-1-released\/\" target=\"_blank\" rel=\"noopener\">statement<\/a><\/strong>.<\/p>\n<p>&#8220;These versions contain important security fixes, and we strongly recommend that all GitLab installations be upgraded to one of these versions immediately. GitLab.com is already running the patched version.&#8221;<\/p>\n<p>By exploiting the flaw, a malicious actor can take over a target machine, steal or delete code, or trick project managers into accepting and running malicious code.<\/p>\n<p>GitLab recommends using a workaround for those unable to install the security updates.<\/p>\n<p>The workaround involves disabling GitHub import, a tool used to transfer entire software projects from GitHub to GitLab.<\/p>\n<p>To apply the workaround, users can follow these steps:<\/p>\n<ol>\n<li>Log in using an administrator account to your GitLab installation.<\/li>\n<li>Click <em>Menu<\/em>, then <em>Admin<\/em>.<\/li>\n<li>Select <em>Settings<\/em>, then <em>General<\/em>.<\/li>\n<li>Expand the <em>Visibility and access control<\/em> tab.<\/li>\n<li>Disable the <em>GitHub option<\/em> under <em>Import sources<\/em>.<\/li>\n<li>Hit <em>Save changes<\/em>.<\/li>\n<\/ol>\n<p>Users can verify if the workaround has been applied correctly by attempting to import a project. If successful, they will not see <em>GitHub<\/em> as an import option.<\/p>\n<hr \/>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/457675-microsoft-finds-severe-security-flaw-in-chromeos.html\" target=\"_blank\" rel=\"noopener\">Microsoft finds severe security flaw in ChromeOS<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>The vulnerability has been assigned a Common Vulnerability Scoring System v3 of 9.9 out of 10.<\/p>\n","protected":false},"author":341076,"featured_media":457953,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[11253,56114],"class_list":["post-457949","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-github","tag-gitlab"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/457949"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=457949"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/457949\/revisions"}],"predecessor-version":[{"id":458003,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/457949\/revisions\/458003"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/457953"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=457949"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=457949"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=457949"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}