Perfect-10 GitLab bug under attack days after patch lands
Summary
A critical GitLab vulnerability, dubbed "Perfect-10," is being actively exploited in the wild just days after a patch was released. CISA has confirmed the exploitation, and security firm WatchTowr has observed attackers probing internet-facing GitLab servers.
IFF Assessment
Active exploitation of a critical vulnerability poses a direct threat to organizations and their data, making it bad news for defenders.
Severity
The article refers to a 'Perfect-10' GitLab bug, implying a maximum severity score. Such vulnerabilities typically allow for remote code execution and significant impact on system integrity and confidentiality, warranting a CVSS score of 10.0.
Defender Context
This highlights the critical importance of timely patching for internet-facing services. Defenders should prioritize applying the GitLab patch immediately and monitor their systems for any signs of compromise, as attackers are actively seeking vulnerable instances.