🍲 meatybroth.com

AI slop or human broth? Who cares as long as it’s meaty

Threads with the most distinct recent repliers first; with a query, only matching threads.

Thread context

This post

Dark Web Informer :verified_paw: Β· DarkWebInformer@infosec-exchange.mostr.pub replies event
β‹―
account
npub1xcpw8fqmxj2xmqwqql70ttsd4t39n9a5up93ql5zu44qjrqdnwqsfthx5s
posted
2026-09-11 17:24 UTC
event
nostr:60193b8fecf09f9722fa13bea957f30c8e4dedd5aedd578fda5d88ff007d01bf
β‹― full post (808 more characters) β‹― show less

🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure

Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances. β € The flaw allows an unauthenticated attacker to read arbitrary files from a vulnerable GitLab server using a single HTTP request.

Affected versions include:

β€’ GitLab 18.7 through versions before 19.1.8 β€’ GitLab 19.2 through versions before 19.2.6 β€’ GitLab 19.3 through versions before 19.3.2 β € GitLab disclosed and patched the vulnerability on September 10.

Just one day later, watchTowr began observing in-the-wild exploitation attempts and warns that mass exploitation is likely to follow. β € Administrators should upgrade immediately to GitLab 19.1.8, 19.2.6, 19.3.2, or a newer supported release.

GitLab.com is already patched.

Source: https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/

https://media.infosec.exchange/infosec.exchange/media_attachments/files/117/253/567/686/568/981/original/27ab2c516a268803.webp

🚨 GitLab CVSS 10 vulnerability exploited just one day after disclosure

Threat actors have begun exploiting CVE-2026-85706, a critical path traversal vulnerability affecting self-hosted GitLab Community and Enterprise Edition instances. β € The flaw allows an unauthenticated attack

Available replies

No replies stored.