GitLab Vulnerability PoC: Exfiltrate and mutate repository via injected template
hackerone.com
hackerone.com
Credit where credit's due to HackerOne co-founder jobert, too. Seems he's made a decent living [0] out of making GitLab more secure.
On the flipside, as a GitLab user, I'm glad to see you guys are so generous with bounties to encourage more detailed (and fascinating) reports like these. :)
[0] https://hackerone.com/jobert?order_direction=DESC&order_fiel...
Best regards, GitLab Security Team
Luckily someone looked at this sooner than a month later! You can see where Google's project zero came in - push for folks to prioritize security.