Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers
ID: 537c07f8-e303-5371-9cad-41d9f451050f
STIX ID: report--537c07f8-e303-5371-9cad-41d9f451050f
Feed Name: The Register (Security)
A critical account-bypass vulnerability (CVE-2023-7028) in self-managed GitLab releases allows attackers to trigger password resets to attacker-controlled unverified email addresses via a crafted HTTP request, enabling account takeover for users without effective 2FA. Multiple GitLab CE/EE 16.x versions are affected; administrators are urged to apply patches immediately, enforce two-factor authentication, or disable password authentication when using external identity providers. The advisory also lists detection checks in production and audit logs and mentions several other fixed vulnerabilities (including CVE-2023-5356 and CVE-2023-4812).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
