Skip to content

[Admin Panel] CSRF to resume/pause runner

Link:          https://hackerone.com/reports/415238
By:            @ngalog

Details: Hi,

Just found a CSRF in admin panel of gitlab instance to pause/resume runner.

Steps to reproduce

Video: https://vimeo.com/292095308 password: lskjflkasjdf

Impact

Just found a CSRF in admin panel of gitlab instance to pause/resume runner.