Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

An update on project runner registration token exposed through issues quick actions vulnerability

Blog post from GitLab

Post Details
Company
Date Published
Author
Kathy Wang
Word Count
406
Company Posts That Month
16
Language
English
Hacker News Points
-
Post removed?
No
Summary

On March 20, 2019, GitLab released a critical security update to address a vulnerability in quick actions for issues that risked exposing project runner registration tokens to unauthorized users, following a report from its HackerOne program. A patch was applied to GitLab.com on March 17, 2019, to mitigate the issue, and a critical security fix was expedited for self-managed customers. On March 24, 2019, GitLab reset runner registration tokens for all projects on GitLab.com, advising users with automation dependent on these tokens to update their scripts with new tokens. An initial investigation found no evidence of security compromise, but GitLab committed to ongoing investigations and improving detection measures. In line with its transparency values, GitLab communicated the incident and apologized for any impact, emphasizing its commitment to information security and intentions to expand its security team. The company later updated its guidance for users affected by the token reset, reinforcing the need for script updates.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.