Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Gitlab: Account Takeover via Password Reset (hackerone.com)
5 points by samber 7 months ago | hide | past | favorite | 3 comments


Great, my account actually just got hit with this. Are we absolutely sure this is solved?

Thank the lord I didn't have anything all that important, and I was in front of my computer to change my password immediately.

As far as I can tell, no one signed into my account. Pretty embarrassing vulnerability tbh...


(2023)


insane




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: