GitLab Releases Updates to Address Critical Vulnerabilities
ID: c3af5dbe-0d33-595c-8ef5-c6ddf84fcfc2
STIX ID: report--c3af5dbe-0d33-595c-8ef5-c6ddf84fcfc2
Feed Name: Dark Reading
GitLab has released critical security updates (16.7.2, 16.6.3, 16.5.6) to remediate multiple vulnerabilities across many versions, including CVE-2023-7028 (authentication flaw allowing password resets to unverified email addresses, CVSS 10) and CVE-2023-5356 (improper authorization enabling impersonation to execute slash commands). The advisory lists affected version ranges, additional CVEs related to CODEOWNERS bypass, workspace namespace issues, and signed-commit metadata modification, and recommends immediate upgrading and enabling two-factor authentication; GitLab has not observed active exploitation of CVE-2023-7028.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
