
3/30/2024 · Shrishti Choudhary
What this post added
This post details GitLab's response to CVE-2024-3094, a critical vulnerability in xz-utils. It confirms that GitLab's core services are unaffected and provides guidance to self-hosted customers on how to check for and mitigate the vulnerability by downgrading or replacing affected versions of xz-utils. It also notes GitHub's action to disable the affected repository.