chief security officer
  • fig. beginning
  • macropolicy
  • Industrial Development
  • CSO·Insight
  • Threat intelligence
  • Data Security
  • privacy protection
  • Cloud security
  • EN
    • CN
    • DE
    • RU
    • TW
    • JP
    • KR
Sign in Sign up
Creation Center
  1. chief security officerHome
  2. intelligence gathering

GitLab Releases Security Patches to Fix High-Risk Vulnerabilities

chief security officer • January 14, 2024 at 6:36 pm • intelligence gathering • 9635 views

GitLab has released a security update that fixes two critical vulnerabilities, one of which (CVE-2023-7028) allows an attacker to exploit a flaw in the mailbox authentication process to hijack a user account by sending a password reset email to an unauthenticated mailbox. The vulnerability affects multiple versions of GitLab Community Edition (CE) and Enterprise Edition (EE).GitLab has released a fix and advises users to upgrade to the fixed version as soon as possible and enable dual authentication for added security.

summarize

GitLab has released a security update that fixes two critical vulnerabilities, one of which can be exploited for account hijacking without user interaction.

Vulnerability Details

CVE-2023-7028

The vulnerability, numbered CVE-2023-7028, received the highest rating of 10.0 in the CVSS scoring system, and allows an attacker to hijack an account by simply sending a password reset email to an unauthenticated email address.

The vulnerability stems from a flaw in the mailbox validation process that allows users to reset their passwords via a secondary mailbox.

Affected versions

All unmanaged instances of GitLab Community Edition (CE) and Enterprise Edition (EE) that use the following versions are affected:

  • Version 16.1, less than 16.1.6
  • Version 16.2, less than 16.2.9
  • Version 16.3, less than 16.3.7
  • Version 16.4, less than 16.4.5
  • Version 16.5, less than 16.5.6
  • Version 16.6, less than 16.6.4
  • Version 16.7, less than 16.7.2

Restoration measures

GitLab said it fixed the vulnerability in GitLab versions 16.5.6, 16.6.4, and 16.7.2 and ported the fix to versions 16.1.6, 16.2.9, 16.3.7, and 16.4.5.

suggestion

To mitigate potential threats, it is recommended that you upgrade your instance to the fixed version as soon as possible and enable dual authentication, especially for users with elevated privileges, and double-check even if you have previously enabled dual authentication.

Original article by Chief Security Officer, if reproduced, please credit https://www.cncso.com/en/gitlab-releases-security-patch-to-fixed-high-risk-vulnerabilities.html

2FA VerificationCVE-2023-7028GitLab Security BulletinGitLab Vulnerabilitiesaccount hijacking attack
Like (0)
0 0
Generate poster

About the author

chief security officer

chief security officer

137 posts
4 comments
1 questions
3 answers
6 followers
Chief Security Officer (cncso.com)
Five years of safe operation practice summary and future thinking
Previous January 12, 2024 at 9:25 pm
Critical Remote Code Execution (RCE) Vulnerability Found in Juniper SRX Firewalls and EX Switches
Next January 14, 2024 at 7:45 pm
chief security officer
chief security officer
chief security officer

Chief Security Officer (cncso.com)

137 posts
4 comments
1 questions
3 answers
6 followers

Table of contentsToggle Table of ContentToggle

  • GitLab Releases Security Patches to Fix High-Risk Vulnerabilities
      • summarize
      • Vulnerability Details
      • Affected versions
      • Restoration measures
      • suggestion

Popular Recommendations

  • Google Zero Trust Architecture Practice
    275.1K

    Google Zero Trust Architecture Practice

  • WPS Office for windows is dealing with a certain OLE mechanism remote code vulnerability

    WPS Office for windows is dealing with a certain OLE mechanism remote code vulnerability

    61.9K
  • StripChat adult video website vulnerability leaks sensitive data of tens of millions of users

    StripChat adult video website vulnerability leaks sensitive data of tens of millions of users

    52.5K
  • Alibaba Cloud Zero Trust Practice: Identity and Network Micro-Isolation in Production Networks

    Alibaba Cloud Zero Trust Practice: Identity and Network Micro-Isolation in Production Networks

    34.6K
  • Practice and exploration of consumer personal information protection in takeaway business scenarios

    Practice and exploration of consumer personal information protection in takeaway business scenarios

    27.1K
  • AIGC Artificial Intelligence Safety Report 2024

    AIGC Artificial Intelligence Safety Report 2024

    26.5K
  • Security Parallel: Next Generation Native Security Infrastructure

    Security Parallel: Next Generation Native Security Infrastructure

    24.8K
  • New secure infrastructure: Alibaba data asset blueprint

    New secure infrastructure: Alibaba data asset blueprint

    24.6K
  • [Critical] Remote code execution vulnerability in open source Apache Log4j

    [Critical] Remote code execution vulnerability in open source Apache Log4j

    22.2K
  • China's new development in the digital era, network security has entered a new era

    China's new development in the digital era, network security has entered a new era

    21.8K
chief security officer
  • fig. beginning
  • Creation Center
  • Privacy Policy
  • Personal center
  • about Us
  • Sitemap
  • CN
  • EN
  • DE

Copyright © 2020 Chief Security Officer. All Rights Reserved.
浙ICP备2023041448号 | Zhejiang Public Network Security No. 33011002017423