GitLab issues patch for high severity account takeover vulnerability

GitLab has released patches for seven vulnerabilities, including a high severity flaw that allowed threat actors to take over people's accounts.

The highlight of the security advisory is an XSS weakness in the VS code editor (Web IDE), which threat actors can exploit via malicious pages. Although attackers can abuse the flaw without authentication, the bug still requires interaction from the victim, making abusing the bug somewhat more complex.

scroll to top