5 ms·
No details, just like the posts about this yesterday. Obligatory 'check our blog later for more.'
by paraxisi 10y ago
No details, just like the posts about this yesterday. Obligatory 'check our blog later for more.'
- puddintane 10y agoIt would be nice to know what versions are affected now but I can understand that they may not want to reveal that until it's patched to prevent any unauthorized access of private repositories.
- pfg 10y agoFrom an email they sent out two days ago: The following versions are affected: 8.7.0 8.6.0 through 8.6.7 8.5.0 through 8.5.11 8.4.0 through 8.4.9 8.3.0 through 8.3.8 8.2.0 through 8.2.4 Not sure why this wasn't included here.
- markwakeford 10y agoIs it a specific mailing list ? I didn't get anything.
- puddintane 10y agoThank you mam/sir!* I should jump on that mailing list ASAP
- jrochkind1 10y agoThat's pretty much the only way to do a security update for something people are going to want to patch asap. warn people in advance it's coming so they can be ready to apply when released, without giving away any details that might help someone find the exploit before it comes.
- mkj 10y agoThey could say what the exposure is. If it's just "your private repos are exposed" then it wouldn't be urgent to patch a public server, for example.
- therein 10y agoLet's hope it's not remote code execution on the CI daemons.
- jrochkind1 10y agoIf they're not saying, I assume it's something really terrible. If it's not something really terrible, then all the advance notice advertising is perhaps cry-wolf overkill.
- fortytw2 10y agoYesterday there wasn't even an official post for 8+ hours after the mail to the mailing list. Great that gitlab notifies people about security issues and tries to fix them... but no points for transparency here
- jobvandervoort 10y agoThere are not a lot of things at GitLab that we don't disclose if we have the option to be open about it. [0] In this case, we can't disclose any more than we did so far. We'll probably do a public post-mortem of the entire process once it's behind us. [0]: https://about.gitlab.com/primer/ https://about.gitlab.com/primer/