• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
cisa warns of active exploitation of severe gitlab password reset

CISA Warns of Active Exploitation of Severe GitLab Password Reset Vulnerability

You are here: Home / General Cyber Security News / CISA Warns of Active Exploitation of Severe GitLab Password Reset Vulnerability
May 2, 2024

The U.S. Cybersecurity and Infrastructure Security Company (CISA) has added a critical flaw impacting GitLab to its Recognized Exploited Vulnerabilities (KEV) catalog, owing to energetic exploitation in the wild.

Tracked as CVE-2023-7028 (CVSS rating: 10.), the highest severity vulnerability could aid account takeover by sending password reset emails to an unverified email tackle.

GitLab, which disclosed information of the shortcoming previously this January, claimed it was introduced as portion of a code adjust in edition 16.1. on Could 1, 2023.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“In these versions, all authentication mechanisms are impacted,” the firm mentioned at the time. “In addition, customers who have two-factor authentication enabled are vulnerable to password reset but not account takeover as their 2nd authentication factor is required to login.”

Thriving exploitation of the issue can have critical consequences as it not only allows an adversary to consider handle of a GitLab consumer account, but also steal sensitive information, qualifications, and even poison source code repositories with destructive code, top to offer chain attacks.

Cybersecurity

“For occasion, an attacker gaining entry to the CI/CD pipeline configuration could embed malicious code made to exfiltrate sensitive details, such as Individually Identifiable Info (PII) or authentication tokens, redirecting them to an adversary-controlled server,” cloud security firm Mitiga reported in a new report.

“Likewise, tampering with repository code may require inserting malware that compromises process integrity or introduces backdoors for unauthorized accessibility. Malicious code or abuse of the pipeline could guide to facts theft, code disruption, unauthorized entry, and supply chain attacks.”

The flaw has been addressed in GitLab variations 16.5.6, 16.6.4, and 16.7.2, with the patches also backported to variations 16.1.6, 16.2.9, 16.3.7, and 16.4.5.

CISA has still to supply any other aspects as to how the vulnerability is currently being exploited in real-earth attacks. In light of active people, federal businesses are necessary to utilize the latest fixes by May possibly 22, 2024, to protected their networks.

Uncovered this article exciting? Abide by us on Twitter  and LinkedIn to go through extra special content material we article.


Some parts of this short article are sourced from:
thehackernews.com

Previous Post: «new cuttlefish malware hijacks router connections, sniffs for cloud credentials New Cuttlefish Malware Hijacks Router Connections, Sniffs for Cloud Credentials
Next Post: New “Goldoon” Botnet Targets D-Link Routers With Decade-Old Flaw new "goldoon" botnet targets d link routers with decade old flaw»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.