CI/CDschedulingCodeownersbypass../Leaky rolepermissionsOAuth/ OIDCBannedusers notactuallybannedSAMLPackageregistryGraphQLAuthnbypassAIHTMLinjectionImpropertokenrevocationEmojisArbitrarypipelineexecutionUserimpersonationPrivilegeescalationPagesdomainhijackMavendependencyproxySensitivedataexposure(Re)DoSCI/CDvariableexposureCSRF /SSRFMergerequestbypassCI/CDschedulingCodeownersbypass../Leaky rolepermissionsOAuth/ OIDCBannedusers notactuallybannedSAMLPackageregistryGraphQLAuthnbypassAIHTMLinjectionImpropertokenrevocationEmojisArbitrarypipelineexecutionUserimpersonationPrivilegeescalationPagesdomainhijackMavendependencyproxySensitivedataexposure(Re)DoSCI/CDvariableexposureCSRF /SSRFMergerequestbypass

GitLab Security Updates - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
  1. CI/CD scheduling
  2. Codeowners bypass
  3. ../
  4. Leaky role permissions
  5. OAuth / OIDC
  6. Banned users not actually banned
  7. SAML
  8. Package registry
  9. GraphQL
  10. Authn bypass
  11. AI
  12. HTML injection
  13. Improper token revocation
  14. Emojis
  15. Arbitrary pipeline execution
  16. User impersonation
  17. Privilege escalation
  18. Pages domain hijack
  19. Maven dependency proxy
  20. Sensitive data exposure
  21. (Re)DoS
  22. CI/CD variable exposure
  23. CSRF / SSRF
  24. Merge request bypass