Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Gitlab 15.11.2 – Important notice – Critical security release
2 points by salzig on May 5, 2023 | hide | past | favorite | 2 comments
No article so far. Just a heads up.


the git repo has more info about the 15.11.2 release: https://gitlab.com/gitlab-org/gitlab/-/commit/d5dc7d794ce2fc...

- Only maintainers of projects should be able to assign runners to them (gitlab-org/security/gitlab@c52abfffad2c06c2a49788e3db473f14923c3926), merge request (gitlab-org/security/gitlab!3234)

- Authorize access to vulnerabilitiesCountByDay resolver (gitlab-org/security/gitlab@8e78aecb9a6c248099a043f181de3c8f6d4417ce)

and a bit of further digging shows the commit for the first issue mentioned above, adding a permission check: https://gitlab.com/gitlab-org/gitlab/-/commit/c52abfffad2c06...


GitLab team member here.

The release post has been published and can be found here: https://about.gitlab.com/releases/2023/05/05/critical-securi...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: