logo

High-severity GitLab flaw lets attackers take over accounts

ID: 0c384d35-7517-5732-a0de-c885eaca341a

STIX ID: report--0c384d35-7517-5732-a0de-c885eaca341a

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-05-23

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

GitLab released urgent security updates (17.0.1, 16.11.3, 16.10.6) to fix a high-severity XSS in the VS Code Web IDE (CVE-2024-4835) that can enable account takeover via malicious pages, plus six medium-severity flaws; the report warns of supply-chain and account-hijacking risks and notes active exploitation of a separate earlier vulnerability (CVE-2023-7028).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.