Security Control Framework
Group Runner Registration Token Vulnerability

Group Runner Registration Token Vulnerability

4/10/2019 · Kathy Wang

What this post added

This post details a security vulnerability where Group Runner Registration Tokens were exposed. A patch was deployed to GitLab.com, and tokens were reset. Critical security releases were issued for GitLab Enterprise Edition to address this vulnerability. No evidence of unauthorized project access was found. Self-managed customers were advised to upgrade.

Read the original post ↗