Lucene search

K
hiveproHiveForce LabsHIVEPRO:469B4D57278B626FF40957CA73EB4772
HistoryJan 18, 2024 - 3:10 p.m.

GitLab Fixes Critical Account Takeover Vulnerability

2024-01-1815:10:14
HiveForce Labs
www.hivepro.com
25
gitlab
vulnerability
account takeover
unauthorized
email verification
two-factor authentication
security update

7.3 High

AI Score

Confidence

Low

0.96 High

EPSS

Percentile

99.5%

Summary: Critical GitLab vulnerability (CVE-2023-7028) enables unauthorized users to take over the administrator account without user interaction. Exploiting password reset flaws, attackers can submit two emails, both target as well as attacker account leading to complete account takeover. Users with two-factor authentication are safe, and GitLab urges immediate updates for affected versions to mitigate the issue in email verification. Threat Level - Red | Vulnerability Report For a detailed threat advisory, download the pdf file here To receive real-time threat advisories, please follow HiveForce Labs on LinkedIn.