mox@lemmy.sdf.org to Programming@programming.dev · 7 months agoMaximum-severity GitLab flaw allowing account hijacking under active exploitationarstechnica.comexternal-linkmessage-square6fedilinkarrow-up1130
arrow-up1128external-linkMaximum-severity GitLab flaw allowing account hijacking under active exploitationarstechnica.commox@lemmy.sdf.org to Programming@programming.dev · 7 months agomessage-square6fedilink
minus-squaresolrize@lemmy.worldlinkfedilinkarrow-up38·7 months agoSomehow they let attackers send themselves password reset links to arbitrary Gitlab accounts, apparently. Not good.
Somehow they let attackers send themselves password reset links to arbitrary Gitlab accounts, apparently. Not good.