April 11, 2024, 6:15 p.m. | Aidas Petryla

DEV Community dev.to

Recently I’ve experienced a GitLab security incident.

Had a pretty new GitLab version (~2 months old), but there were a few security patches released. Apparently, I was missing one of them.


I noticed GitLab throwing 500 errors randomly and later 502 consistently. Looking at the server I’ve noticed some processes run by “git” user, which shouldn't be running, consuming all CPU. Processes were restarting after killing them. Updating GitLab to the newest version resolved the issue.


Keeping software up-to-date can …

beginners devops errors gitlab incident incidents missing old patches processes run security security incident security patches server simple version

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Technical Support Specialist (Cyber Security)

@ Sigma Software | Warsaw, Poland

OT Security Specialist

@ Adani Group | AHMEDABAD, GUJARAT, India

FS-EGRC-Manager-Cloud Security

@ EY | Bengaluru, KA, IN, 560048