chief security officer
  • macropolicy
  • Industrial Development
  • CSO·Insight
  • Threat intelligence
  • Data Security
  • privacy protection
  • Cloud security
  • en_USEN
    • de_DEDE
    • ru_RURU
    • zh_CNCN
    • zh_TWTW
    • jaJP
    • ko_KRKR
Sign in Sign up
Creation Center
  1. chief security officerHome
  2. intelligence gathering

GitLab Releases Security Patches to Fix High-Risk Vulnerabilities

chief security officer • January 14, 2024 at 6:36 pm • intelligence gathering • 8462 views

GitLab has released a security update that fixes two critical vulnerabilities, one of which (CVE-2023-7028) allows an attacker to exploit a flaw in the mailbox authentication process to hijack a user account by sending a password reset email to an unauthenticated mailbox. The vulnerability affects multiple versions of GitLab Community Edition (CE) and Enterprise Edition (EE).GitLab has released a fix and advises users to upgrade to the fixed version as soon as possible and enable dual authentication for added security.

Table of contents

  • summarize
  • Vulnerability Details
  • Affected versions
  • Restoration measures
  • suggestion

summarize

GitLab has released a security update that fixes two critical vulnerabilities, one of which can be exploited for account hijacking without user interaction.

Vulnerability Details

CVE-2023-7028

The vulnerability, numbered CVE-2023-7028, received the highest rating of 10.0 in the CVSS scoring system, and allows an attacker to hijack an account by simply sending a password reset email to an unauthenticated email address.

The vulnerability stems from a flaw in the mailbox validation process that allows users to reset their passwords via a secondary mailbox.

Affected versions

All unmanaged instances of GitLab Community Edition (CE) and Enterprise Edition (EE) that use the following versions are affected:

  • Version 16.1, less than 16.1.6
  • Version 16.2, less than 16.2.9
  • Version 16.3, less than 16.3.7
  • Version 16.4, less than 16.4.5
  • Version 16.5, less than 16.5.6
  • Version 16.6, less than 16.6.4
  • Version 16.7, less than 16.7.2

Restoration measures

GitLab said it fixed the vulnerability in GitLab versions 16.5.6, 16.6.4, and 16.7.2 and ported the fix to versions 16.1.6, 16.2.9, 16.3.7, and 16.4.5.

suggestion

To mitigate potential threats, it is recommended that you upgrade your instance to the fixed version as soon as possible and enable dual authentication, especially for users with elevated privileges, and double-check even if you have previously enabled dual authentication.

Original article by Chief Security Officer, if reproduced, please credit https://www.cncso.com/en/gitlab-releases-security-patch-to-fixed-high-risk-vulnerabilities.html

2FA VerificationCVE-2023-7028GitLab Security BulletinGitLab Vulnerabilitiesaccount hijacking attack
Like (0)
0 0
Generate poster

About the author

chief security officer

chief security officer

126 posts
4 comments
1 questions
3 answers
5 followers
Chief Security Officer (cncso.com)
Five years of safe operation practice summary and future thinking
Previous January 12, 2024 at 9:25 pm
Critical Remote Code Execution (RCE) Vulnerability Found in Juniper SRX Firewalls and EX Switches
Next January 14, 2024 at 7:45 pm
chief security officer
chief security officer
chief security officer

Chief Security Officer (cncso.com)

126 posts
4 comments
1 questions
3 answers
5 followers

Recent Posts

  • CSO:2025年中国网络安全从合规到AI驱动风险治理趋势
  • Data Security Intelligence Body: AI-driven paradigm for next-generation enterprise data security protection
  • AI Security:Artificial Intelligence AI Attack Surface Analysis Report 2026
  • Global Cyber Attack Landscape and AI Security Threat Report 2025
  • AI Security: Building an Enterprise AI Security System Based on ATT&CK Methodology
  • AI IDE Security: Cursor Windsurf Google Antigravity Supply Chain Attack Analysis
  • CSO:2025 Artificial Intelligence (AI) Cyber Attack and Defense Statistics, Trends, Costs, and Defense Security Report
  • CSO: A Chief Security Officer's Guide to Full-Link Security for Artificial Intelligence Data
  • The MCP Governance Framework: How to build a next-generation security model that resists AI superpowers
  • AI security architecture: from AI capabilities to security platform landing practice

Recommended reading

  • CSO:2025年中国网络安全从合规到AI驱动风险治理趋势

    CSO:2025年中国网络安全从合规到AI驱动风险治理趋势

    2026年1月18日

  • Data Security Intelligence Body: AI-driven paradigm for next-generation enterprise data security protection

    Data Security Intelligence Body: AI-driven paradigm for next-generation enterprise data security protection

    January 13, 2026

  • AI Security:Artificial Intelligence AI Attack Surface Analysis Report 2026

    AI Security:Artificial Intelligence AI Attack Surface Analysis Report 2026

    January 10, 2026

  • Global Cyber Attack Landscape and AI Security Threat Report 2025

    Global Cyber Attack Landscape and AI Security Threat Report 2025

    January 9, 2026

  • AI Security: Building an Enterprise AI Security System Based on ATT&CK Methodology

    AI Security: Building an Enterprise AI Security System Based on ATT&CK Methodology

    January 9, 2026

  • AI IDE Security: Cursor Windsurf Google Antigravity Supply Chain Attack Analysis

    AI IDE Security: Cursor Windsurf Google Antigravity Supply Chain Attack Analysis

    January 7, 2026

  • Large model security: open source framework Guardrails security fence introduction and analysis

    Large model security: open source framework Guardrails security fence introduction and analysis

    January 6, 2026

  • CSO:2025 Artificial Intelligence (AI) Cyber Attack and Defense Statistics, Trends, Costs, and Defense Security Report

    CSO:2025 Artificial Intelligence (AI) Cyber Attack and Defense Statistics, Trends, Costs, and Defense Security Report

    January 4, 2026

  • CSO: A Chief Security Officer's Guide to Full-Link Security for Artificial Intelligence Data

    CSO: A Chief Security Officer's Guide to Full-Link Security for Artificial Intelligence Data

    December 31, 2025

  • The MCP Governance Framework: How to build a next-generation security model that resists AI superpowers

    The MCP Governance Framework: How to build a next-generation security model that resists AI superpowers

    December 30, 2025

chief security officer
  • fig. beginning
  • My Account
  • Creation Center
  • Privacy Policy
  • safe community
  • about Us
  • Sitemap

Copyright © 2020 Chief Security Officer. All Rights Reserved.
浙ICP备2023041448号 | Zhejiang Public Network Security No. 33011002017423