
"GitLab Issues Urgent Patch for Zero-Click Account Hijacking Vulnerability"
GitLab has issued security updates for its Community and Enterprise Editions to address critical vulnerabilities, including a zero-click account hijacking flaw (CVE-2023-7028) that allows attackers to take over accounts without user interaction. The flaw affects versions 16.1 to 16.7 and could lead to the compromise of proprietary code and sensitive data. Other vulnerabilities include the abuse of Slack/Mattermost integrations and bypassing CODEOWNERS approval. Users are strongly advised to update their installations as soon as possible.


