by @jakaba
03 Apr 2024

Critical GitLab account takeover vulnerability (CVE-2023-7028)

by @jakaba
03 Apr 2024

Critical GitLab account takeover vulnerability (CVE-2023-7028)

CVEs

9.8 Critical Severity

Apps

Gitlab
GitlabGitlab
15.11.11.*
15.11.2.*
16.5.6.*
16.5.7.*
16.9.8.*
16.9.7.*
13.11.7.*
13.11.6.*
13.11.5.*
16.8.7.*

Screenshots from the blog posts

images/clujg0ec1e5671hnd18l77fst.jpgimages/clujg0ec1e5671hnd18l77fst.jpg

Summary

GitLab swiftly addressed a critical vulnerability, CVE-2023-7028, affecting versions 16.1 to 16.7.1, by releasing patches to prevent account takeovers via unverified email password resets, highlighting the importance of quick response to security threats in maintaining user trust and safety.

Description

users/photos/clj8b3h1k16g10uoihwvzgsxi.png

@jakaba

74 posts

Total vcoins

64.3K

Social media links

Comments (0)