Skip to main content
Room Banner
Back to all walkthroughs
Room Icon

GitLab CVE-2023-7028

Max room.

Learn to exploit a GitLab instance using CVE-2023-7028 and understand various mitigation techniques.

medium

60 min

6,190

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

GitLab is a renowned and widely adopted web-based repository manager that provides a comprehensive platform for source code management, continuous integration, and collaboration in software development projects. Per the latest stats (opens in new tab), the platform ranks first for / and tools, surpassing other vital platforms like GitHub, Azure, , etc. In Jan 2024, the platform identified a critical vulnerability in its Community (CE) and Enterprise Edition (EE) that allows unauthorised users to take over user accounts, potentially including administrator accounts, without any interaction from the victim. The vulnerability was identified by asterion04 (opens in new tab) through a private bug bounty program and was assigned the severity Critical and CVE-ID 2023-7028.

Learning Objectives
  • Exploit a GitLab CE instance through 2023-7028
  • How the exploit works
  • Protection and mitigation measures
Room Prerequisites
Understanding the following topics is recommended before starting the room: Let's begin!
Answer the questions below
I am ready to explore the room.