Skip Navigation

Over 5,300 GitLab servers exposed to zero-click account takeover attacks

www.bleepingcomputer.com /news/security/over-5-300-gitlab-servers-exposed-to-zero-click-account-takeover-attacks/
Embed prevented alt text
49
Security News @infosec.pub Blaze @lemmy.zip
Over 5,300 GitLab servers exposed to zero-click account takeover attacks

You're viewing a single thread.

49 comments
  • Check gitlab-rails/production_json.log for HTTP requests to the /users/password path with params.value.email consisting of a JSON array with multiple email addresses.

    Jesus Christ. Their frontend was sending a list of recipients to the backend. That's an intern developer level of fuck up, in their login system, no less.

    If this got past them, it's a sign of deep problems.

49 comments