security6 publishers
GitLab's 19.3.2 release closes an unauthenticated arbitrary file read in the commits API
GitLab shipped 19.3.2, 19.2.6 and 19.1 to fix a maximum-severity path traversal that needs no account, plus an Enterprise Edition deserialization bug that needs a Duo Chat user. GitLab.com is already patched.
Publishers:bleepingcomputer.comcyberscoop.comhorizon3.aiscworld.comsecurityweek.comthehackernews.com
Reality
- Evidence58
- Adoption45
- Hype gap+12
- Incentives55
- Confidence52