SSH Key Management and Authentication
FAQ: The RegreSSHion vulnerability and GitLab

FAQ: The RegreSSHion vulnerability and GitLab

7/9/2024 · Mark Loveless

What this post added

This post details the RegreSSHion vulnerability (CVE-2024-6387), a remote unauthenticated code execution flaw in OpenSSH server. It explains how GitLab.com and GitLab Dedicated are not impacted due to the use of `gitlab-sshd`, which is not vulnerable. For self-managed customers, it advises applying OS patches or configuring `gitlab-sshd` for mitigation, and emphasizes general security best practices like regular patching and MFA. It also notes the low real-world success rate of the exploit.

Read the original post ↗