The GitLab File-Read Patch Needs a Secret Map
| 21 min read
For Developers GitLab fixed a flaw that let an unauthenticated visitor read server files on affected self-managed installations. Patch promptly, then use a concrete secret map to decide what evidence to preserve and which credentials may need replacing.