Security Research

CVE-2023-7028 GitLab Account Takeover: dual-recipient password reset

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of GitLab password reset dual-mail flow

GitLab’s password reset flow lets a single request deliver mail to multiple addresses. The attacker appends their own inbox to the victim’s reset request and takes over the account.

Unlock to view this content.