TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template

65 点作者 jakejarvis大约 6 年前

4 条评论

sytse大约 6 年前
Very proud of our security team for the responsive communication and ensuring the issue is made public <a href="https:&#x2F;&#x2F;gitlab.com&#x2F;gitlab-org&#x2F;gitlab-ce&#x2F;issues&#x2F;54189#note_128763324" rel="nofollow">https:&#x2F;&#x2F;gitlab.com&#x2F;gitlab-org&#x2F;gitlab-ce&#x2F;issues&#x2F;54189#note_12...</a>
评论 #19330483 未加载
评论 #19330292 未加载
评论 #19332736 未加载
conradk大约 6 年前
It looks like it took Gitlab only a day to verify and release a fix for this issue. That&#x27;s quick!
privateSFacct大约 6 年前
Thank you for submitting this report. We will investigate the issue as soon as possible. Due to our current workload, we will get back within <i>20 business days</i> with an update.<p>Best regards, GitLab Security Team<p>Luckily someone looked at this sooner than a month later! You can see where Google&#x27;s project zero came in - push for folks to prioritize security.
评论 #19330764 未加载
评论 #19331292 未加载
评论 #19330627 未加载
I_have_receipts大约 6 年前
It would be really cool to see a blog post on how this was handled internally. IR team notification, escalation paths, internal verification, how the product team was notified, determining priority, how you decide when to disclose vs not, etc.