logo

Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers

ID: 537c07f8-e303-5371-9cad-41d9f451050f

STIX ID: report--537c07f8-e303-5371-9cad-41d9f451050f

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-01-15

Date Updated: 2026-04-26

Author: Connor Jones

...
...

A critical account-bypass vulnerability (CVE-2023-7028) in self-managed GitLab releases allows attackers to trigger password resets to attacker-controlled unverified email addresses via a crafted HTTP request, enabling account takeover for users without effective 2FA. Multiple GitLab CE/EE 16.x versions are affected; administrators are urged to apply patches immediately, enforce two-factor authentication, or disable password authentication when using external identity providers. The advisory also lists detection checks in production and audit logs and mentions several other fixed vulnerabilities (including CVE-2023-5356 and CVE-2023-4812).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.