- the problem appeared in GitLab 11.9.0
- the problem seems to have been fixed in GitLab 13.8.8
- the vulnerability uses ExifTool, so to exploit it, a user needs to be able to upload images
- if an update is not (yet) possible, DjVu format file uploads can be blocked to avert this vulnerability
- this vulnerability isn't relevant for GitLab instances that just have 1 user, or are not publicly accessible on the Internet
Now, i'm not saying that the above is entirely true, but after reading something like the above, one should be able to figure out how to best act: - if you have a public GitLab instance with open registrations, consider updating it immediately (with backups in place, of course)
- if you have a private GitLab instance with many users in your own corporate network (that somehow isn't updated yet) - this is a good reason to put updating it into your agenda today, even if your users aren't necessarily hostile
- if you have a private GitLab instance or one with registrations closed (e.g. you're the only user or people that you trust use it), mark this down and update whenever possible, however it's probably not necessary right this moment
Of course, i can't say the above with 100% confidence, because the article itself lacks this actionable information to aid in decisionmaking and so i'm left to piece things together on my own, because of which i could be wrong.On an unrelated note, DjVu is a pretty interesting file format, though sadly i've only seen it be used very sparsely, on some Russian forums for tractor manuals or something: https://en.wikipedia.org/wiki/DjVu