Linux,
@Linux@sakurajima.social avatar

⚠️ GitLab Security Flaw (exploit) ⚠️

No matter if you host your own copy of GitLab Software or use GitLab's servers directly, you should enable 2-step Verification - NOW (right now, do not wait). There is a current exploit that allows someone to hijack GitLab Accounts, who are not using 2-step verification.

arcadetoken,
@arcadetoken@autistics.life avatar

@Linux Is there a ZDI or CVE ID that's dropped for it yet?

Linux,
@Linux@sakurajima.social avatar

@arcadetoken Yes, here is the link to the news story (see URL). The vulnerability, tracked as CVE-2023-7028, carries a severity rating of 10 out of a possible 10. https://arstechnica.com/security/2024/05/0-click-gitlab-hijacking-flaw-under-active-exploit-with-thousands-still-unpatched/

ParadeGrotesque,
@ParadeGrotesque@mastodon.sdf.org avatar

@Linux

10/10? Oooof...

@arcadetoken

  • All
  • Subscribed
  • Moderated
  • Favorites
  • opensource
  • DreamBathrooms
  • mdbf
  • InstantRegret
  • Durango
  • Youngstown
  • rosin
  • slotface
  • thenastyranch
  • osvaldo12
  • ngwrru68w68
  • kavyap
  • cisconetworking
  • khanakhh
  • magazineikmin
  • anitta
  • cubers
  • vwfavf
  • modclub
  • everett
  • ethstaker
  • normalnudes
  • tacticalgear
  • tester
  • provamag3
  • GTA5RPClips
  • Leos
  • megavids
  • JUstTest
  • All magazines