GitLab recently patched a high-severity flaw that could let threat actors take over user accounts by weaponizing it in cross-site scripting (XSS) attacks.
The vulnerability, tracked as CVE-2024-4835, is an XSS flaw in GitLab’s VS code editor, potentially enabling threat actors to steal restricted information through malicious pages.
The vulnerability is currently flagged as highly severe, but has yet to receive an official CVSS severity rating. According to its description page, the flaw affects GitLab versions 15.11 before 16.10.6, 16.11 before 16.11.3, and 17.0 before 17.0.1.
“By leveraging this condition, an attacker can craft a malicious page to exfiltrate sensitive user information,” reads the description.
Although threat actors could exploit this shortcoming without authentication, the attack would still require some user interaction, making it more complex.
After learning of the situation, GitLab addressed the issue by rolling out patched versions of GitLab Community (CE) and Enterprise (EE) Editions.
"Today, we are releasing versions 17.0.1, 16.11.3, and 16.10.6 for GitLab Community Edition (CE) and Enterprise Edition (EE)," reads GitLab’s patch release note. "These versions contain important bug and security fixes, and we strongly recommend that all GitLab installations be upgraded to one of these versions immediately."
Threat actors frequently aim to hijack accounts on software development platforms like GitLab and GitHub. Control of these accounts can facilitate further malicious activities, including supply chain attacks that might compromise entire repositories and affect all users frequently interacting with them.
Last month, a vulnerability was discovered on GitHub, allowing threat actors to host and distribute malware through the platform’s content delivery network (CDN). The issue was also found to affect GitLab.
Hijacked accounts on development platforms are often hard to spot, exposing users to inadvertently downloading malware-ridden programs, patches or code. Dedicated security software like Bitdefender Ultimate Security can help you dodge rogue downloads from compromised repositories.
It encompasses advanced security features, including comprehensive monitoring and protection against intrusions such as viruses, worms, Trojans, zero-day exploits, ransomware, and spyware, a network threat prevention module, and behavioral detection technology that takes instant action upon detecting suspicious activity in apps.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all postsNovember 14, 2024
September 06, 2024