logo

Federal frenzy to patch gaping GitLab account takeover hole

ID: 761b97b8-dae5-5106-bac9-866d848bcf37

STIX ID: report--761b97b8-dae5-5106-bac9-866d848bcf37

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-05-02

Date Updated: 2026-04-26

Author: Connor Jones

...
...

CISA has added GitLab CVE-2023-7028 to its Known Exploited Vulnerabilities list after reports of active exploitation; the improper access control bug (introduced in v16.1.0) allows an attacker to trigger a password reset to an attacker-controlled unverified email and achieve full account takeover. Multiple GitLab 16.x releases are affected (numerous versions listed), patches and backports are available, Shadowserver reports ~2,149 exposed instances remaining, and accounts protected by 2FA are not vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.