CI/CDschedulingPagesdomainhijackOAuth/ OIDCEmojisLeaky rolepermissionsCSRF /SSRF../PackageregistryArbitrarypipelineexecutionMavendependencyproxyGraphQLUserimpersonationImpropertokenrevocationAuthnbypassPrivilegeescalation(Re)DoSSensitivedataexposureBannedusers notactuallybannedCodeownersbypassSAMLCI/CDvariableexposureAIHTMLinjectionMergerequestbypassCI/CDschedulingPagesdomainhijackOAuth/ OIDCEmojisLeaky rolepermissionsCSRF /SSRF../PackageregistryArbitrarypipelineexecutionMavendependencyproxyGraphQLUserimpersonationImpropertokenrevocationAuthnbypassPrivilegeescalation(Re)DoSSensitivedataexposureBannedusers notactuallybannedCodeownersbypassSAMLCI/CDvariableexposureAIHTMLinjectionMergerequestbypass

GitLab Security Updates - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
  1. CI/CD scheduling
  2. Pages domain hijack
  3. OAuth / OIDC
  4. Emojis
  5. Leaky role permissions
  6. CSRF / SSRF
  7. ../
  8. Package registry
  9. Arbitrary pipeline execution
  10. Maven dependency proxy
  11. GraphQL
  12. User impersonation
  13. Improper token revocation
  14. Authn bypass
  15. Privilege escalation
  16. (Re)DoS
  17. Sensitive data exposure
  18. Banned users not actually banned
  19. Codeowners bypass
  20. SAML
  21. CI/CD variable exposure
  22. AI
  23. HTML injection
  24. Merge request bypass