5379 GitLab Servers are Vulnerable to Zero-Click Account Takeover Attacks
ID: 306be8c7-faae-5c28-b9e7-4d0cdf55d054
STIX ID: report--306be8c7-faae-5c28-b9e7-4d0cdf55d054
Feed Name: cybersecurityNews.com
**GitLab released critical security updates for CE/EE (16.7.2 / 16.6.4 / 16.5.6) addressing multiple CVEs including a critical account-takeover flaw (CVE-2023-7028) that could allow resetting passwords to unverified addresses; other issues include CODEOWNERS approval bypass, Slack/Mattermost integration abuse, remote development access control, and commit signature metadata modification.** The advisory lists affected versions, notes ShadowServer telemetry indicating ~5,379 potentially vulnerable servers, confirms patches are available, and states there is no evidence of in-the-wild exploitation while recommending prompt upgrades and log review for indicators of attempted abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
