Gitlab: Account Takeover via Password Reset

by samberon 2/26/2025, 12:59 PMwith 3 comments

by dimglon 2/27/2025, 1:03 AM

Great, my account actually just got hit with this. Are we absolutely sure this is solved?

Thank the lord I didn't have anything all that important, and I was in front of my computer to change my password immediately.

As far as I can tell, no one signed into my account. Pretty embarrassing vulnerability tbh...

by zoidbon 2/26/2025, 3:13 PM

(2023)

by net01on 2/27/2025, 12:35 AM

insane