SSL/TLS Security Enhancements
GitLab's response to curl and libcurl security vulnerability

GitLab's response to curl and libcurl security vulnerability

10/12/2023 · Joseph Longo

What this post added

This post details GitLab's investigation and response to the curl and libcurl security vulnerability (CVE-2023-38545). It confirms that GitLab.com and GitLab Dedicated environments are not affected due to the absence of SOCKS5 proxy configuration. For self-managed customers using SOCKS5 proxies with GitLab, the post advises upgrading to curl version 8.4.0. The security and development teams proactively scoped the usage of curl and libcurl across the GitLab environment to assess potential impact.

Read the original post ↗