GitLab shares GitHub’s vulnerability to hosting malware
15:22, 23.04.2024
GitLab proved to be also vulnerable to GitHub’s vulnerability to posting malware with the help of URL addresses connected to Microsoft repositories.
The vulnerability is related to the comment feature, where one can attach links with a unique URL address in the following format: https://www.github.com/{project_user}/{repo_name}/files/{file_id}/{file_name}» .
The links may be generated while creating a commit comment for repositories of popular and reputable projects and then remain active even in the case the comment hasn’t been published.
The users can attach any files creating a download link for them, and cyber attackers discovered that they can use the feature for sharing malware.
The same vulnerability has been detected in GitLab CDN where links have the following format: https://gitlab.com/{project_group_namr}/{repo_name}/uploads/{file_id}/{file_name}.
Was this article helpful to you?
VPS popular offers
-
-21.5%€/mo€ 26 /moBilled annuallyCPU2 Xeon CoresRAM2 GBSpace75 GB SSDBandwidth300 GB
-
-20.5%€/mo€ 95 /moBilled annuallyCPU6 Xeon CoresRAM16 GBSpace150 GB SSDBandwidth10 TB
-
-15%€/mo€ 176 /moBilled annuallyOSCentOSCPU10 Epyc CoresRAM64GBSpace300 GB NVMeSoftwareKeitaroBandwidthUnlimited
-
-9.1%€/mo€ 66 /moBilled annuallyCPU4 Xeon CoresRAM4 GBSpace100 GB SSDBandwidthUnlimited
-
-20.6%€/mo€ 59 /moBilled annuallyCPU6 Xeon CoresRAM8GBSpace100GB SSDBandwidth500GB
-
-6.3%€/mo€ 111 /moBilled annuallyCPU4 Xeon CoresRAM8 GBSpace100 GB SSDBandwidthUnlimited
-
-10.2%€/mo€ 88 /moBilled annuallyOSCentOSCPU8 Epyc CoresRAM32 GBSpace200 GB NVMeSoftwareKeitaroBandwidthUnlimited
-
-8%€/mo€ 29.5 /moBilled annuallyCPU4 Epyc CoresRAM4 GBSpace50 GB NVMeBandwidthUnlimited
-
-9.1%€/mo€ 55 /moBilled annuallyCPU4 Xeon CoresRAM4 GBSpace50 GB SSDBandwidthUnlimited
-
-9.1%€/mo€ 165 /moBilled annuallyCPU10 Xeon CoresRAM64 GBSpace300 GB SSDBandwidthUnlimited