CISA Warns of Active Exploitation of Severe GitLab Password Reset Vulnerability
ID: 47c5cbe7-4584-501b-99f2-d8eda05d7cfb
STIX ID: report--47c5cbe7-4584-501b-99f2-d8eda05d7cfb
Feed Name: The Hacker News
CISA added CVE-2023-7028 — a critical GitLab vulnerability (CVSS 10.0) that enables account takeover via password-reset to unverified email addresses — to its Known Exploited Vulnerabilities catalog due to active exploitation. GitLab introduced the flaw in v16.1.0 (May 1, 2023) and has released fixes in 16.5.6/16.6.4/16.7.2 and backports; federal agencies were required to apply fixes by May 22, 2024. The report warns of serious impacts including account takeover, credential theft, and possible supply-chain attacks if CI/CD or repositories are compromised.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
