mox@lemmy.sdf.org to Programming@programming.dev · 8 months agoMaximum-severity GitLab flaw allowing account hijacking under active exploitationarstechnica.comexternal-linkmessage-square6fedilinkarrow-up1140arrow-down12cross-posted to: technology@lemmy.zip
arrow-up1138arrow-down1external-linkMaximum-severity GitLab flaw allowing account hijacking under active exploitationarstechnica.commox@lemmy.sdf.org to Programming@programming.dev · 8 months agomessage-square6fedilinkcross-posted to: technology@lemmy.zip
minus-squaresolrize@lemmy.worldlinkfedilinkarrow-up39·8 months agoSomehow they let attackers send themselves password reset links to arbitrary Gitlab accounts, apparently. Not good.
Somehow they let attackers send themselves password reset links to arbitrary Gitlab accounts, apparently. Not good.