Skip to content
Techzine Europe
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Europe
  • Techzine Netherlands
Techzine News Security GitLab accounts vulnerable to takeover, patch available
2 min Security

GitLab accounts vulnerable to takeover, patch available

Erik van KlinkenJanuary 12, 2024 3:26 pmJanuary 12, 2024 3:26 pm
GitLab accounts vulnerable to takeover, patch available

GitLab is warning users about a critical vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE). The vulnerability in question, CVE-2023-7028, allows hackers to take over accounts. Patches have already been released.

According to GitLab, the CVE-2023-7028 vulnerability makes it possible to easily take over accounts. Namely, this can be done by having emails to reset passwords delivered to an unverified email address. Those without 2FA enabled could lose access to their own accounts without the new patch.

When CE and Enterprise end users do use 2FA to log into their accounts, the vulnerability only allows hackers to reset passwords. The accounts cannot then be taken over as the external authentication method is required after a password change request.

Problem with email authentication

The vulnerability was itself introduced by GitLab with the release of the GitLab CE and Enterprise editions v 16.1.0. This included the ability to reset a password via a second email address. The bug in question ended up in the email verification process.

No active exploits yet

The bug has been active since May 2023, but may have remained unknown outside of GitLab itself. Active exploits of the vulnerability are therefore not known, but GitLab urges users who host the platform themselves to check their own log files carefully.

The development platform has already patched the bug and released updated versions 16.7.2, 16.6.4 and 16.5.6 for both editions. End users should implement the updates as soon as possible, GitLab indicates.

Also read: GitLab 16 unveiled

Tags:

account takeover / CVE-2023-7028 / GitLab / vulnerability

"*" indicates required fields

Stay tuned, subscribe!

Nieuwsbrieven*
This field is for validation purposes and should be left unchanged.

Related

Vulnerability in GitLab assistant enabled code theft

Chrome vulnerability allowing account takeover fixed

SAP confirms NetWeaver vulnerability is being actively exploited

SAP patches zero-day vulnerability in NetWeaver, denies exploitation

Editor picks

What we know about SafePay, the Ingram Micro attackers

It sounds like a banking app, but instead, it's one of the latest ran...

Amazon S3: almost 20 years old, but still very modern

From backup vault to foundational layer

Dutch Authority: Data theft via ransomware doubles in one year

In 2024, cybercriminals stole personal data almost twice as often as ...

HPE closes acquisition of Juniper Networks

Together for top spot

Insight: Data Fabrics

New Alteryx release tears down walls between cloud services and datasets

Data company Alteryx aims to give companies more control over their d...

Wikidata unlocks its own knowledge base by vectorizing its data

Initiative for the benefit of open-source AI models

SAP Datasphere makes data access easier

SAP Datasphere makes data access easier

SAP Datasphere is the evolution of Data Warehouse Cloud. The new prod...

Microsoft Fabric will be like Office, but for data platforms

Microsoft Fabric will be like Office, but for data platforms

Native Cosmos DB, Power BI agent, and Digital Twin

Read more on Security

Did Marks & Spencer pay a ransom to its cyber attackers?

Did Marks & Spencer pay a ransom to its cyber attackers?

And does it matter?

Erik van Klinken 15 hours ago
No Android security patch this month, ending a 10-year streak

No Android security patch this month, ending a 10-year streak

For the first time since August 2015, Google has not released any security updates for Android this month. Ho...

Erik van Klinken 17 hours ago
Critical Citrix NetScaler vulnerability leaks memory data

Critical Citrix NetScaler vulnerability leaks memory data

A new critical vulnerability in Citrix NetScaler, designated CVE-2025-5777 and now known in the security comm...

Mels Dees 22 hours ago
Zscaler Cellular brings Zero Trust to IoT and OT devices
Top story

Zscaler Cellular brings Zero Trust to IoT and OT devices

In August, Zscaler will launch a cellular solution that brings Zero Trust security to IoT and OT devices. Wit...

Berry Zwets 16 hours ago

Whitepapers

Experience Synology’s latest enterprise backup solution

Experience Synology’s latest enterprise backup solution

How do you ensure your company data is both secure and quickly recove...

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Tech calendar

Krijg Volledig Inzicht van Gebruiker tot Cloud met Cisco ThousandEyes

July 15, 2025

GITEX DIGI_HEALTH 5.0 - Thailand

September 10, 2025 BITEC Bangkok, Thailand

IT Arena

September 26, 2025 Lviv, Ukraine

Innovation Week 2025

October 9, 2025 Prague

Luxembourg Venture Days

October 22, 2025 Luxembourg

Appdevcon

March 10, 2026 Amsterdam

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2025 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement