logo

GitLab warns of critical zero-click account hijacking vulnerability

ID: f5319217-c8a3-5a07-b556-4df4a0ab4ade

STIX ID: report--f5319217-c8a3-5a07-b556-4df4a0ab4ade

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2024-01-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GitLab released urgent security updates addressing multiple critical flaws, including CVE-2023-7028 (a 10/10 zero-click password reset/authentication issue enabling account takeover) and CVE-2023-5356 (abuse of Slack/Mattermost integrations); affected versions across 16.1–16.7 are listed and fixes/backports provided, with GitLab recommending immediate updates and offering log-based indicators of compromise for detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.