-
-
Notifications
You must be signed in to change notification settings - Fork 255
Unauthenticated GitLab SSRF - CI Lint API [CVE-2021-22214] #236
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
The DCO check is failing, the commits should be fixed up. |
|
This pull request introduces 1 alert when merging 9a16df5 into fd99a0a - view on LGTM.com new alerts:
|
|
Updated, please review! |
|
This pull request introduces 3 alerts when merging 655f55f into b8e06ef - view on LGTM.com new alerts:
|
|
Thanks for that screenshot by the way, that helps make things make more sense. I wasn't aware that GitLab had a private (or personal) hosted solution. (Though I also didn't bother to read up on the CVE you'd quoted 🤷 ) |
|
Ah, Gitlab offers community and enterprise editions that can be hosted privately and many enterprises prefer to manage their codebase through these private gitlab instances. Moreover, there's a high chance this issue might be prevalent on those instances since upgrading Gitlab can prove to be quite a bit of hassle. 😛 |
kingthorin
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good to me
Signed-off-by: Prince Mendiratta <prince.mendiratta@getastra.com>
|
Fixed up the commits. |
|
Thank you! |
kingthorin
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks
#235 - Unauthenticated GitLab SSRF - CI Lint API [CVE-2021-22214]
Signed-off by: prince.mendiratta@getastra.com