What is the vulnerability?A critical vulnerability has been discovered in GitLab, a DevOps platform for managing software development lifecycle. A successful exploitation of the vulnerability may allow an attacker to take control of the GitLab administrator account without user interaction. CVE-2023-7028 has been given a maximum CVSS score of 10. CISA added the vulnerability on May 1st to its Known Exploited Vulnerabilities (KEV) Catalog.What is the recommended Mitigation?GitLab users are advised to update their instances to a patched version and enable two factor authentication (2FA) which will deny malicious actors access to compromised accounts.What FortiGuard Coverage is available?FortiGuard Labs has an existing Web Application Security signature “GitLab.Password.Reset.Account.Takeover” released on Jan 16 to detect and block any attack attempts targeting the Authentication Bypass Vulnerability in GitLab (CVE-2023-7028) and has Endpoint Vulnerability signature ID “5551” to detect vulnerable versions of installed GitLab software.
More Stories
chromium-135.0.7049.95-1.fc42
FEDORA-2025-fb323a2b22 Packages in this update: chromium-135.0.7049.95-1.fc42 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.fc40
FEDORA-2025-7827e4feac Packages in this update: chromium-135.0.7049.95-1.fc40 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.el10_1
FEDORA-EPEL-2025-af0c337351 Packages in this update: chromium-135.0.7049.95-1.el10_1 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.el9
FEDORA-EPEL-2025-5104c5b9be Packages in this update: chromium-135.0.7049.95-1.el9 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
chromium-135.0.7049.95-1.fc41
FEDORA-2025-9c1d536035 Packages in this update: chromium-135.0.7049.95-1.fc41 Update description: Update to 135.0.7049.95 CVE-2025-3619: Heap buffer overflow in Codecs CVE-2025-3620: Use after...
caddy-2.10.0-1.fc43
FEDORA-2025-89401f2116 Packages in this update: caddy-2.10.0-1.fc43 Update description: Update to version 2.10.0. Aside from the new upstream features, this update...