Collected research
GitLab RCE via GitHub import
Shows how attacker-controlled GitHub import data becomes Sawyer objects whose to_s and bytesize methods can be overridden. Redis command construction then emits inconsistent protocol framing, allowing arbitrary Redis commands and the injection of jobs that lead to remote code execution.
Record
- Published by
- GitLab
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of GitLab, first published at the original source. Preserved copies are kept so the citation survives its host.