Riccardo Padovani 1/26/2025

Responsible disclosure: improper access control in Gitlab private project.

Read Original

This article details a responsible disclosure case of an improper access control vulnerability in GitLab. A user removed from a private group could retain access to projects where their role was changed. The post outlines the vulnerability's impact, the lengthy and poorly communicated disclosure timeline with GitLab, and the eventual $2000 bounty award, while critiquing the process.

Responsible disclosure: improper access control in Gitlab private project.

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser