Responsible disclosure: improper access control in Gitlab private project.
Read OriginalThis article details a responsible disclosure case of an improper access control vulnerability in GitLab. A user removed from a private group could retain access to projects where their role was changed. The post outlines the vulnerability's impact, the lengthy and poorly communicated disclosure timeline with GitLab, and the eventual $2000 bounty award, while critiquing the process.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser