logo

Critical GitLab Bug Under Exploit Enables Account Takeover, CISA Warns

ID: 0433c7ce-937a-5768-9062-402838af325f

STIX ID: report--0433c7ce-937a-5768-9062-402838af325f

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-05-03

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

A critical GitLab vulnerability (CVE-2023-7028, CVSS 10.0) is under active exploitation: attackers can force password resets to addresses they control, enabling account takeover and potential code/data theft or supply-chain tampering; CISA added it to the KEV list and public exploits are available, so immediate patching and mitigations (MFA, PAM, patch fast-track) are strongly advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.