GitLab warns of critical zero-click account hijacking vulnerability
ID: f5319217-c8a3-5a07-b556-4df4a0ab4ade
STIX ID: report--f5319217-c8a3-5a07-b556-4df4a0ab4ade
Feed Name: Bleeping Computer
Threat Score
GitLab released urgent security updates addressing multiple critical flaws, including CVE-2023-7028 (a 10/10 zero-click password reset/authentication issue enabling account takeover) and CVE-2023-5356 (abuse of Slack/Mattermost integrations); affected versions across 16.1–16.7 are listed and fixes/backports provided, with GitLab recommending immediate updates and offering log-based indicators of compromise for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
