A public GitLab 18.11.3 PoC chains two Oj parser bugs through crafted Jupyter notebook diffs to execute commands as git without admin rights.
Developers with GitLab fixed a critical vulnerability in the open source repository manager that could have allowed the theft of application files, tokens, or secrets. Developers with GitLab this week ...