mox@lemmy.sdf.org to Programming@programming.dev · 8 months agoMaximum-severity GitLab flaw allowing account hijacking under active exploitationarstechnica.comexternal-linkmessage-square6fedilinkarrow-up1140arrow-down12cross-posted to: [email protected]
arrow-up1138arrow-down1external-linkMaximum-severity GitLab flaw allowing account hijacking under active exploitationarstechnica.commox@lemmy.sdf.org to Programming@programming.dev · 8 months agomessage-square6fedilinkcross-posted to: [email protected]
minus-squaresolrize@lemmy.worldlinkfedilinkarrow-up39·8 months agoSomehow they let attackers send themselves password reset links to arbitrary Gitlab accounts, apparently. Not good.
Somehow they let attackers send themselves password reset links to arbitrary Gitlab accounts, apparently. Not good.