GitLab closes ten flaws and urges self-managed installs to upgrade
GitLab has published security updates closing ten vulnerabilities in both Community Edition and Enterprise Edition. Four are rated high severity, including cross-site scripting and improper encoding allowing HTML injection. The rest cover denial of service, authentication bypass and information disclosure. Patched versions are 18.6.2, 18.5.4 and 18.4.6. The updates include database migrations that may require downtime on single-node instances, while properly configured clusters can upgrade without downtime. GitLab.com is already patched, and GitLab Dedicated customers need take no action.
What this means for your organisation
GitLab is often where an organisation keeps its source code, build pipelines and operational keys in one place. A breach there is not only read access to code but the ability to change what ships to production. An authentication bypass in such a system undermines traceability across the whole development chain, and with it the ability to document who changed what, which both ISO 27001 and NIS2 assume.
Berigo recommends
- Plan the upgrade to 18.6.2, 18.5.4 or 18.4.6 now, and book a window for the database migration on single-node installs.
- Review who holds maintainer rights across repositories and remove access that is no longer used.
- Audit active access tokens and deploy keys, and shorten their lifetimes.
- Make sure GitLab audit logs are shipped to a system outside GitLab itself.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch