CVE-2024-37301: document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
(updated )
A remote code execution (RCE) via server-side template injection (SSTI) allows for user supplied code to be executed in the server’s context where it is executed as the document-merge-server user with the UID 901 thus giving an attacker considerable control over the container.
References
Detect and mitigate CVE-2024-37301 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →