AuthnbypassPrivilegeescalationPackageregistryCodeownersbypassGraphQLBannedusers notactuallybannedMergerequestbypassHTMLinjection(Re)DoSAIOAuth/ OIDCCI/CDschedulingEmojisCSRF /SSRFSAMLImpropertokenrevocationMavendependencyproxy../Leaky rolepermissionsUserimpersonationArbitrarypipelineexecutionSensitivedataexposureCI/CDvariableexposurePagesdomainhijackAuthnbypassPrivilegeescalationPackageregistryCodeownersbypassGraphQLBannedusers notactuallybannedMergerequestbypassHTMLinjection(Re)DoSAIOAuth/ OIDCCI/CDschedulingEmojisCSRF /SSRFSAMLImpropertokenrevocationMavendependencyproxy../Leaky rolepermissionsUserimpersonationArbitrarypipelineexecutionSensitivedataexposureCI/CDvariableexposurePagesdomainhijack

GitLab Security Updates - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
  1. Authn bypass
  2. Privilege escalation
  3. Package registry
  4. Codeowners bypass
  5. GraphQL
  6. Banned users not actually banned
  7. Merge request bypass
  8. HTML injection
  9. (Re)DoS
  10. AI
  11. OAuth / OIDC
  12. CI/CD scheduling
  13. Emojis
  14. CSRF / SSRF
  15. SAML
  16. Improper token revocation
  17. Maven dependency proxy
  18. ../
  19. Leaky role permissions
  20. User impersonation
  21. Arbitrary pipeline execution
  22. Sensitive data exposure
  23. CI/CD variable exposure
  24. Pages domain hijack