GitLab released security updates for Community Edition and Enterprise Edition to fix multiple vulnerabilities, led by CVE-2023-7028, a critical password reset flaw that could send reset emails to an unverified address and enable account takeover. The issue was assigned a CVSS 10.0 score, and GitLab said GitLab.com had already been patched while it had not detected abuse of the flaw on GitLab-managed platforms. The same release also addressed CVE-2023-5356, which involved abuse of Slack and Mattermost slash commands, along with CVE-2023-4812, CVE-2023-6955, and CVE-2023-2030.
GitLab initially shipped fixes in versions 16.7.2, 16.6.4, and 16.5.6, then advised customers to move to 16.7.3, 16.6.5, 16.5.7, or newer because of an additional database migration issue in the earlier patch set. The company urged self-managed administrators to upgrade promptly, enable 2FA, and review logs for signs of exploitation attempts, reflecting the severity of the account takeover risk and the broader exposure from the other patched flaws.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
After the 2024-01-11 security release, GitLab later told customers to upgrade further to versions 16.7.3, 16.6.5, 16.5.7, or newer because the earlier patch set had an additional DB migration issue. The source does not provide a specific date for this follow-up advisory.
On 2024-01-11, GitLab released versions 16.7.2, 16.6.4, and 16.5.6 for Community Edition and Enterprise Edition to fix multiple vulnerabilities, including the critical account takeover issue CVE-2023-7028. The release also addressed CVE-2023-5356, CVE-2023-4812, CVE-2023-6955, and CVE-2023-2030, and GitLab said GitLab.com was already patched.
The Dutch National Cyber Security Centre (NCSC) reported observing active attempts to exploit GitLab vulnerabilities, including CVE-2023-7028. The advisory also noted that public proof-of-concept exploit code had been published.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcedocs.gitlab.com
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourceabout.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.