CVE-2024-8233 - How a GitLab Diff Bug Could Crash Your Service — Analysis, Exploit Details, and Fixes
On June 26th, 2024, cybersecurity researchers disclosed a new vulnerability in GitLab, tracked as CVE-2024-8233. This bug affects GitLab Community Edition (CE) and Enterprise Edition
CVE-2024-8179 - GitLab Improper Output Encoding Leads to XSS (Exploit Details & Code Example)
In June 2024, a security issue was identified in GitLab Community Edition (CE) and Enterprise Edition (EE), now tracked as CVE-2024-8179. The bug affects GitLab
CVE-2024-12570 - How GitLab CI_JOB_TOKEN Could Leak Your Session Token (Explained with Example)
A serious vulnerability—CVE-2024-12570—has been discovered lurking in GitLab Community Edition (CE) and Enterprise Edition (EE). This security flaw could allow someone who gets
CVE-2024-21574 - How POST Requests to `/customnode/install` Enable Remote Code Execution in Custom Node Extensions
CVE-2024-21574 is a critical vulnerability that left many servers running custom node extensions open to Remote Code Execution (RCE). This post will walk you through
CVE-2024-4109 - How a Flaw in Undertow HTTP/2 Handler Can Leak Your Inflight Secrets
On May 2024, a new security issue—CVE-2024-4109—was disclosed, affecting Red Hat’s highly used web server component, Undertow. If you use WildFly, JBoss,
Episode
00:00:00
00:00:00