Root cause
A secondary-address recovery feature expanded delivery choices without consistently preserving verified-address ownership. The vendor attributes the regression to email verification; recovery authorization must remain bound to trusted account state as features change.
Demonstrated impact
Unauthorized password changes could lead to account takeover. Enforced second-factor authentication still prevented login, but did not prevent password reset. Offering SSO alone did not eliminate exposure when password authentication remained available.
Lessons for review
- Bind recovery delivery to verified account state and validate security-sensitive input contracts.
- Review recovery paths independently of primary authentication and optional SSO.
- Vendor remediation added end-to-end reset tests covering address handling, email generation and content; review the whole recovery contract rather than one validation function.
- Separate patch deployment from compromise assessment; apply the vendor’s incident-response guidance where compromise is suspected.
Award and evidence
USD 1,000 initial plus USD 34,000 additional award for one report. Dollar notation uses HackerOne policy currency context; cash receipt unverified.
Original public report and both award events read in the cloud browser; official vendor release notes independently corroborate the CVE, impact boundary and patched release. Re-read the vendor FAQ to distinguish secondary-address regression, second-factor and SSO boundaries, and documented regression-test coverage.
- Award events do not establish cash settlement.
- The report UI has no CVE field value; CVE association comes from the matching vendor advisory.
- Detailed report publication is not the first public advisory date.
- The advisory’s historical observation of no detected abuse on vendor-managed platforms does not establish present-day absence of compromise or the state of self-managed deployments.
Recorded timeline
- Published
- 2025-02-26explicit · Detailed report publication, later than the vendor advisory.
- Public Disclosure
- 2024-01-11explicit · Public vendor advisory; detailed report followed February 26, 2025.
- Reported
- 2023-12-20explicit
- Awarded
- 2024-01-12explicit · Final award event; initial award December 22, 2023.
- Fixed
- 2024-01-11explicit · Public patched release. GitLab.com was patched earlier; its exact deployment date is not supplied.
Sources and provenance
- Account Takeover via Password Reset without user interactions GitLab and asterion04 · reviewed 2026-10-02
- GitLab Critical Security Release: 16.7.2, 16.6.4, 16.5.6 GitLab · reviewed 2026-10-02
- Vulnerability Disclosure Standards: Bug Bounty payment denomination HackerOne · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.