Urgent: GitLab Releases Patch for Critical Vulnerabilities - Update ASAP
ID: 8f006e8d-bafe-5ada-ba38-b67f31e98300
STIX ID: report--8f006e8d-bafe-5ada-ba38-b67f31e98300
Feed Name: The Hacker News
GitLab released critical security updates for two vulnerabilities: CVE-2023-7028 (CVSS 10.0) — a flaw in the email verification/password reset flow allowing account takeover via an unverified secondary email — and CVE-2023-5356 (CVSS 9.6) — allowing abuse of Slack/Mattermost integrations to execute slash commands as another user. Multiple self-managed CE/EE 16.x versions are affected (introduced in 16.1.0); fixes have been released and backported for specific 16.x releases. Administrators are advised to upgrade immediately and enable 2FA, especially for privileged accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
