CISA orders federal agencies to fix hundreds of exploited security flaws
US sanctions NSO Group and three others for spyware and exploit sales
Microsoft: Windows 11 built-in apps might not open on some systems
BlackMatter ransomware claims to be shutting down due to police pressure
Alleged Twitter hacker charged with theft of $784K in crypto via SIM swaps
Beware: Free Discord Nitro phishing targets Steam gamers
UK Labour Party discloses data breach after ransomware attack
BlackMatter ransomware moves victims to LockBit after shutdown
Qualys BrowserCheck
Junkware Removal Tool
How to remove the PBlock+ adware browser extension
Remove the Search Redirect
Remove the Search Redirect
Remove the Search Redirect
Remove Security Tool and SecurityTool (Uninstall Guide)
How to remove Antivirus 2009 (Uninstall Instructions)
How to Remove WinFixer / Virtumonde / Msevents / Trojan.vundo
How to remove Google Redirects or the TDSS, TDL3, or Alureon rootkit using TDSSKiller
Locky Ransomware Information, Help Guide, and FAQ
CryptoLocker Ransomware Information Guide and FAQ
CryptorBit and HowDecrypt Information Guide and FAQ
CryptoDefense and How_Decrypt Ransomware Information Guide and FAQ
How to make the Start menu full screen in Windows 10
How to install the Microsoft Visual C++ 2015 Runtime
How to open an elevated PowerShell Admin prompt in Windows 10
How to Translate a Web Page in Google Chrome
How to start Windows in Safe Mode
How to remove a Trojan, Virus, Worm, or other Malware
How to show hidden files in Windows 7
How to see hidden files in Windows
IT Certification Courses
Gear + Gadgets
A critical unauthenticated, remote code execution GitLab flaw fixed on April 14, 2021, remains exploitable, with over 50% of deployments remaining unpatched.
The vulnerability is tracked as CVE-2021-22205 and has a CVSS v3 score of 10.0, allowing an unauthenticated, remote attacker to execute arbitrary commands as the ‘git’ user (repository admin).
This vulnerability gives the remote attacker full access to the repository, including deleting, modifying, and stealing source code.
Hackers first started exploiting internet-facing GitLab servers in June 2021 to create new users and give them admin rights.
The actors used a working exploit published on GitHub on June 4, 2021, allowing them to abuse the vulnerable ExifTool component.
The threat actors do not need to authenticate or use a CSRF token or even a valid HTTP endpoint to use the exploit.
With the exploitation continuing to this day, researchers from Rapid7 decided to look into the number of unpatched systems and determine the scope of the underlying problem.
According to a report published by Rapid7, at least 50% of the 60,000 internet-facing GitLab installations they found are not patched against the critical RCE flaw fixed six months ago.
Moreover, another 29% may or may not be vulnerable, as the analysts couldn’t extract the version string for those servers.
Admins need to update to one of the following versions to patch the flaw:
Any versions earlier than that and down to 11.9 are vulnerable to exploitation whether you’re using GitLab Enterprise Edition (EE) or GitLab Community Edition (CE).
For more details on how to update GitLab, check out this dedicated portal.
To ensure that your GitLab instance isn’t vulnerable to exploitation, you can check its response to POST requests that attempt to exploit ExifTool’s mishandling of image files.
The patched versions still allow someone to reach out to ExifTool, but the response to the request should be a rejection in the form of an HTTP 404 error.
CISA urges admins to patch critical Discourse code execution bug
Working exploit released for VMware vCenter CVE-2021-22005 bug
Netgear fixes dangerous code execution bug in multiple routers
Microsoft: Windows MSHTML bug now exploited by ransomware gangs
Microsoft fixes Windows CVE-2021-40444 MSHTML zero-day bug
Not a member yet? Register Now
Microsoft 365 outage blocks access to OneDrive, SharePoint files
Microsoft announces new endpoint security solution for SMBs
To receive periodic updates and news from BleepingComputer, please use the form below.
Terms of Use Privacy PolicyEthics Statement
Copyright @ 2003 – 2021 Bleeping Computer® LLC – All Rights Reserved
Not a member yet? Register Now
Read our posting guidelinese to learn what content is prohibited.


You May Also Like

Six million Sky routers exposed to takeover attacks for 17 months

US regulators order banks to report cyberattacks within 36 hoursHackers deploy Linux…

Customize the Windows 11 experience with these free apps

Hackers exploit Microsoft MSHTML bug to steal Google, Instagram credsApple sues spyware-maker…

Massive attack against 1.6 million WordPress sites underway

ALPHV BlackCat – This year’s most sophisticated ransomwareSonicWall ‘strongly urges’ customers to…

Microsoft offers 50% subscription discounts to Office pirates

Microsoft offers 50% subscription discounts to Office piratesRussian hacking group uses new…