CISA says GitLab account takeover bug is actively exploited in attacks
ID: 7cc43034-92d1-5702-9756-b072c8de1b8e
STIX ID: report--7cc43034-92d1-5702-9756-b072c8de1b8e
Feed Name: Bleeping Computer
CISA warns that CVE-2023-7028, a maximum-severity GitLab improper access control flaw enabling zero-click account hijacking via password reset, is being actively exploited; thousands of GitLab instances were exposed when patches were released and organizations (including U.S. federal agencies) have been ordered to remediate. GitLab published fixes and guidance, 2FA mitigates account takeover risk, and affected parties should apply patches and follow incident-response guidance immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
