Over 5,300 GitLab servers exposed to zero-click account takeover attacks
ID: 5bcba901-3ea6-52fc-852e-c64b8346862d
STIX ID: report--5bcba901-3ea6-52fc-852e-c64b8346862d
Feed Name: Bleeping Computer
GitLab disclosed a critical (CVSS 10.0) zero-click account takeover vulnerability (CVE-2023-7028) affecting multiple 16.x releases; patches were released on 2024-01-11 but ShadowServer reported 5,379 exposed instances still vulnerable, placing affected servers at high risk for account takeover, supply-chain compromise, and code/API secret disclosure. Administrators are advised to apply updates, enable 2FA, rotate secrets if compromised, and use provided log-detection tips to check for exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
