Maximum-severity GitLab flaw allowing account hijacking under active exploitation
Maximum-severity GitLab flaw allowing account hijacking under active exploitation

Maximum-severity GitLab flaw allowing account hijacking under active exploitation

Maximum-severity GitLab flaw allowing account hijacking under active exploitation
Maximum-severity GitLab flaw allowing account hijacking under active exploitation
Somehow they let attackers send themselves password reset links to arbitrary Gitlab accounts, apparently. Not good.