logo

GitLab Releases Updates to Address Critical Vulnerabilities

ID: c3af5dbe-0d33-595c-8ef5-c6ddf84fcfc2

STIX ID: report--c3af5dbe-0d33-595c-8ef5-c6ddf84fcfc2

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-01-12

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

GitLab has released critical security updates (16.7.2, 16.6.3, 16.5.6) to remediate multiple vulnerabilities across many versions, including CVE-2023-7028 (authentication flaw allowing password resets to unverified email addresses, CVSS 10) and CVE-2023-5356 (improper authorization enabling impersonation to execute slash commands). The advisory lists affected version ranges, additional CVEs related to CODEOWNERS bypass, workspace namespace issues, and signed-commit metadata modification, and recommends immediate upgrading and enabling two-factor authentication; GitLab has not observed active exploitation of CVE-2023-7028.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.