Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers

GitLab admins should apply the latest batch of security patches pronto given the new critical account-bypass vulnerability just disclosed. Tracked as CVE-2023-7028, the maximum-severity bug exploits a change introduced in version 16.1.0 back in May 2023 that allowed users to issue password resets through a secondary email address.

Source: The Register

 


Date:

Categorie(s):