Skip to content
Techzine Europe
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Europe
  • Techzine Netherlands
Techzine News Security GitLab accounts vulnerable to takeover, patch available
2 min Security

GitLab accounts vulnerable to takeover, patch available

Erik van KlinkenJanuary 12, 2024 3:26 pmJanuary 12, 2024 3:26 pm
GitLab accounts vulnerable to takeover, patch available

GitLab is warning users about a critical vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE). The vulnerability in question, CVE-2023-7028, allows hackers to take over accounts. Patches have already been released.

According to GitLab, the CVE-2023-7028 vulnerability makes it possible to easily take over accounts. Namely, this can be done by having emails to reset passwords delivered to an unverified email address. Those without 2FA enabled could lose access to their own accounts without the new patch.

When CE and Enterprise end users do use 2FA to log into their accounts, the vulnerability only allows hackers to reset passwords. The accounts cannot then be taken over as the external authentication method is required after a password change request.

Problem with email authentication

The vulnerability was itself introduced by GitLab with the release of the GitLab CE and Enterprise editions v 16.1.0. This included the ability to reset a password via a second email address. The bug in question ended up in the email verification process.

No active exploits yet

The bug has been active since May 2023, but may have remained unknown outside of GitLab itself. Active exploits of the vulnerability are therefore not known, but GitLab urges users who host the platform themselves to check their own log files carefully.

The development platform has already patched the bug and released updated versions 16.7.2, 16.6.4 and 16.5.6 for both editions. End users should implement the updates as soon as possible, GitLab indicates.

Also read: GitLab 16 unveiled

Tags:

account takeover / CVE-2023-7028 / GitLab / vulnerability

"*" indicates required fields

Stay tuned, subscribe!

Nieuwsbrieven*
This field is for validation purposes and should be left unchanged.

Related

Chrome vulnerability allowing account takeover fixed

SAP confirms NetWeaver vulnerability is being actively exploited

SAP patches zero-day vulnerability in NetWeaver, denies exploitation

Apple patches dangerous zero-day vulnerability

Editor picks

Microsoft introduces huge security risk in OneDrive

Microsoft is rolling out a new OneDrive feature that synchronizes dat...

Wiz is “Deployed on AWS” despite Google acquisition

From now on, Wiz will also run natively on AWS. With this "Deployed o...

How Nutanix uses Nutanix

Large IT players have the advantage that their own solutions can also...

ServiceNow aims to disrupt Salesforce with new AI-based CRM

The battle of the titans

Insight: Security Platforms

Upwind adds API security capabilities to cloud security platform

Upwind adds real-time API security to the Cloud Application Detection...

Cisco AI Defense enables secure deployment of AI

Further expansion for Cisco's security platform

Cybersecurity in 2023: Is it five to or five past twelve?

Cybersecurity in 2023: Is it five to or five past twelve?

No day in the cyber world looks the same. With attack frequency and s...

Security industry is fundamentally broken: base investments on hard evidence

Security industry is fundamentally broken: base investments on hard evidence

Many security investments do not deliver what was expected or hoped f...

Read more on Security

Hack on Coinbase exposes vulnerability of crypto industry

Hack on Coinbase exposes vulnerability of crypto industry

Cryptocurrency platform Coinbase has announced that it has been the victim of a hack. Although the financial ...

Berry Zwets 3 hours ago
Cybercriminals are circumventing multi-factor authentication

Cybercriminals are circumventing multi-factor authentication

Multi-factor authentication (MFA) is no longer the strong line of defense it used to be. Although MFA has lon...

Mels Dees 6 hours ago
Proofpoint strengthens position in MSP market with acquisition of Hornetsecurity

Proofpoint strengthens position in MSP market with acquisition of Hornetsecurity

Proofpoint has announced the acquisition of Hornetsecurity, a German security provider that focuses primarily...

Sander Almekinders 22 hours ago
Rise of AI transforms CISO’s role: from technical to strategic input
Top story

Rise of AI transforms CISO’s role: from technical to strategic input

Sam Curry, CISO at Zscaler talks strategy and (future) challenges

Sander Almekinders 2 hours ago

Whitepapers

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Try the latest high-end Synology backup system for free

Try the latest high-end Synology backup system for free

How do you ensure that your data is secure and can be quickly restore...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Tech calendar

Red Hat Summit

May 19, 2025 Boston

Ontdek de kracht van Microsoft Copilot in het MBO

June 4, 2025 Schiphol

Thales on Tour

June 5, 2025 Duffel

Kaseya DattoCon Europe

June 17, 2025 Dublin

Nutanix Cloud Day Nederland 2025

June 17, 2025 Zeist

Nürnberg Digital Festival 2025

June 30, 2025 Nürnberg

Tech career

AI & Data Architect

Full time

Cloud Account Executive – Slack

Amsterdam Full time

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2025 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement