from Hacker News

Gitlab: Account Takeover via Password Reset

by samber on 2/26/25, 12:59 PM with 3 comments

  • by dimgl on 2/27/25, 1:03 AM

    Great, my account actually just got hit with this. Are we absolutely sure this is solved?

    Thank the lord I didn't have anything all that important, and I was in front of my computer to change my password immediately.

    As far as I can tell, no one signed into my account. Pretty embarrassing vulnerability tbh...

  • by zoidb on 2/26/25, 3:13 PM

    (2023)
  • by net01 on 2/27/25, 12:35 AM

    insane