SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  GitLab CE/EE Password Manipulation

Category: WEB-ATTACKS      

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address. Hit to this signature indicates possible attempt to reset known user password using the exploit. The destination system may need to be inspected in case this action is not anticipated.


Relevant Information