CI/CDvariableexposureBannedusers notactuallybannedImpropertokenrevocationCSRF /SSRFEmojisAuthnbypassLeaky rolepermissions(Re)DoSUserimpersonation../CI/CDschedulingSAMLCodeownersbypassArbitrarypipelineexecutionAIPackageregistryPagesdomainhijackPrivilegeescalationGraphQLOAuth/ OIDCSensitivedataexposureHTMLinjectionMavendependencyproxyMergerequestbypassCI/CDvariableexposureBannedusers notactuallybannedImpropertokenrevocationCSRF /SSRFEmojisAuthnbypassLeaky rolepermissions(Re)DoSUserimpersonation../CI/CDschedulingSAMLCodeownersbypassArbitrarypipelineexecutionAIPackageregistryPagesdomainhijackPrivilegeescalationGraphQLOAuth/ OIDCSensitivedataexposureHTMLinjectionMavendependencyproxyMergerequestbypass

GitLab Security Updates - Call List

(Print) Use this randomly generated list as your call list when playing the game. There is no need to say the BINGO column name. Place some kind of mark (like an X, a checkmark, a dot, tally mark, etc) on each cell as you announce it, to keep track. You can also cut out each item, place them in a bag and pull words from the bag.


1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
  1. CI/CD variable exposure
  2. Banned users not actually banned
  3. Improper token revocation
  4. CSRF / SSRF
  5. Emojis
  6. Authn bypass
  7. Leaky role permissions
  8. (Re)DoS
  9. User impersonation
  10. ../
  11. CI/CD scheduling
  12. SAML
  13. Codeowners bypass
  14. Arbitrary pipeline execution
  15. AI
  16. Package registry
  17. Pages domain hijack
  18. Privilege escalation
  19. GraphQL
  20. OAuth / OIDC
  21. Sensitive data exposure
  22. HTML injection
  23. Maven dependency proxy
  24. Merge request bypass