Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities
depthfirst.com | research | #rce | #featured | #vulnerability-research | #gitlab | #ruby | #memory-safety | #memory-corruption | #oj-parser
Summary
We chained two memory-safety flaws in Oj, a native Ruby JSON parser used by GitLab's notebook diff renderer, into remote code execution in a Puma worker. The path begins with an attacker-controlled Jupyter notebook and crosses GitLab, ipynbdiff, CRuby, and jemalloc before reaching function-pointer control.
- Published
- Collected
Skip to content