Skip to content
Techzine Global
  • Home
  • Topstories
  • Topics
    • Analytics
    • Applications
    • Collaboration
    • Data Management
    • Devices
    • Devops
    • Infrastructure
    • Privacy & Compliance
    • Security
  • Insights
    • All Insights
    • Agentic AI
    • Analytics
    • Cloud ERP
    • Generative AI
    • IT in Retail
    • NIS2
    • RSAC 2025 Conference
    • Security Platforms
    • SentinelOne
  • More
    • Become a partner
    • About us
    • Contact us
    • Terms and conditions
    • Privacy Policy
  • Techzine Global
  • Techzine Netherlands
  • Techzine Belgium
  • Techzine TV
  • ICTMagazine Netherlands
  • ICTMagazine Belgium
Techzine » News » Security » More than 5,000 GitLab instances still vulnerable to account takeover
2 min Security

More than 5,000 GitLab instances still vulnerable to account takeover

Floris Hulshoff PolJanuary 25, 2024 10:23 amJanuary 25, 2024 10:23 am
More than 5,000 GitLab instances still vulnerable to account takeover

5,379 GitLab instances are still at risk. These instances may be affected by the recently discovered GitLab account vulnerability. ShadowServer research shows that accounts can still be taken over.

Recently, GitLab was affected by the critical vulnerability CVE-2023-7028. GitLab has since fixed this with a patch. However, ShadowServer research shows that many users have yet to install this patch. Potential risks include supply chain attacks, disclosure of proprietary code, API key leaks and other malicious activities.

Most vulnerable instances are in the U.S., totaling 964, followed by Germany (730), Russia (721), China (503), France (298), the UK (122), India (117) and Canada (99). However, no specific breaches have been reported at the time of writing.

Een schermafbeelding van een website met een kaart van de wereld.

Features CVE-2023-7028

This vulnerability for GitLab instances allows attackers to perform a so-called zero-click attack to take control of instances.

This vulnerability allows hackers to send password reset emails for an attacked GitLab account to an email address they control. This way, they can then change the password and take over the account. However, when 2FA is enabled, this is blocked.

Fixes already released for some time

The problem occurs in GitLab Community and Enterprise Edition version 16.1 for 16.1.5, version 16.2 for 16.2.8, version 16.3 for 16.3.6, version 16.4 for 16.4.4, version 16.5 for 16.5.6, version 16.6 for 16.6.4 and version 16.7 for 16.7.2.

Two weeks ago, patches were released for versions 16.7.2, 16.5.6 and 16.6.4, as well as backporting patches for versions16.1.6, 16.2.9 and 16.3.7.

GitLab urges companies to still check their systems after implementing the updates for possible changes to their development environment, including source code and potentially modified files.

Also read: GitLab accounts vulnerable to takeover, patch available

Tags:

account takeover / CVE-2023-7028 / GitLab / instance

"*" indicates required fields

Stay tuned, subscribe!

Nieuwsbrieven*
This field is for validation purposes and should be left unchanged.

Related

Chrome vulnerability allowing account takeover fixed

More than 178,000 SonicWall firewalls vulnerable to simple DoS attack

GitLab accounts vulnerable to takeover, patch available

11 million servers still vulnerable to Terrapin SSH attack

Editor picks

Intel’s CEO survives baptism of fire, will his company do the same?

US President Donald Trump appears to have changed his mind. Having ca...

Cohere now worth $6.8B: what makes the AI startup stand out?

AI company Cohere is now worth $6.8 billion after another successful ...

Preview: Google Pixel 10 series targets iPhone stalwarts

The new series of Google Pixel phones has been unveiled. Visually, li...

Printers play a central role in HP’s workplace vision

Innovation in software, AI, and security

Techzine.tv

What is HPE VM Essentials and is it a direct competitor to VMware?

What is HPE VM Essentials and is it a direct competitor to VMware?

Better servers and storage have direct impact on wine sales and marketing

Better servers and storage have direct impact on wine sales and marketing

HPE's rise as a credible virtualization player started with Morpheus acquisition

HPE's rise as a credible virtualization player started with Morpheus acquisition

The impact of OpsRamp on HPE and its integration into the stack

The impact of OpsRamp on HPE and its integration into the stack

Read more on Security

NIS2 is intended to make organizations more secure, but will it succeed?
Top story

NIS2 is intended to make organizations more secure, but will it succeed?

NIS2 hasn't been converted into national law in every EU country, despite the deadline set for October 2024. ...

Erik van Klinken August 18, 2025
Zscaler and CrowdStrike deepen SecOps collaboration

Zscaler and CrowdStrike deepen SecOps collaboration

Zscaler and CrowdStrike have expanded their partnership. This comes shortly after Zscaler's definitive acquis...

Erik van Klinken 17 hours ago
The many victims of Salesforce attacker ShinyHunters
Top story

The many victims of Salesforce attacker ShinyHunters

Google, Cisco, Air France-KLM, Chanel...

Erik van Klinken August 7, 2025
Orange Belgium reports cyberattack: 850,000 accounts compromised

Orange Belgium reports cyberattack: 850,000 accounts compromised

Telecom operator Orange Belgium was the victim of a cyberattack at the end of July, in which hackers gained a...

Erik van Klinken 19 hours ago

Expert Talks

Meeting future workload demands: the case for emerging memory technologies

Meeting future workload demands: the case for emerging memory technologies

It often feels as though memory is an outlier in the technology world...

How AI and automation are redefining ROI in the enterprise

How AI and automation are redefining ROI in the enterprise

Today’s data and business analysts are equipped with a wide array o...

Enhancing video encoding: The AV1 support in the new ARTPEC-9 System-on-Chip

In an era where video security and digital technologies are evolving ...

Simplifying complexity: Bridging the cloud skills gap

In recent years, there has been a seismic shift away from traditional...

Tech calendar

NULLCON Berlin 2025

September 4, 2025 Courtyard By Marriott, Berlin City Center

bit summit

September 4, 2025 Hamburg

GITEX DIGI_HEALTH 5.0 - Thailand

September 10, 2025 BITEC Bangkok, Thailand

VeeamON Tour 2025

September 18, 2025 Driebergen-Rijsenburg

IT Arena

September 26, 2025 Lviv, Ukraine

Innovation Week 2025

October 9, 2025 Prague

Whitepapers

Experience Synology’s latest enterprise backup solution

Experience Synology’s latest enterprise backup solution

How do you ensure your company data is both secure and quickly recove...

How to choose the right Enterprise Linux platform?

How to choose the right Enterprise Linux platform?

"A Buyer's Guide to Enterprise Linux" comprehensively analyzes the mo...

Enhance your data protection strategy for 2025

The Data Protection Guide 2025 explores the essential strategies and...

Strengthen your cybersecurity with DNS best practices

The white paper "DNS Best Practices" by Infoblox presents essential g...

Techzine Global

Techzine focusses on IT professionals and business decision makers by publishing the latest IT news and background stories. The goal is to help IT professionals get acquainted with new innovative products and services, but also to offer in-depth information to help them understand products and services better.

Follow us

Twitter
LinkedIn
YouTube

© 2025 Dolphin Publications B.V.
All rights reserved.

Techzine Service

  • Become a partner
  • Advertising
  • About Us
  • Contact
  • Terms & Conditions
  • Privacy Statement