📄 Reading a GitLab Vulnerability Report — Account Takeover via Password Reset
In this video, I go over a real vulnerability report that explains how an attacker could reset a GitLab user’s password without any interaction from the victim — just by knowing their email address. We'll break down the report step by step, understand the technical details, and discuss the impact and responsible disclosure behind the finding.
🧠 Whether you're new to bug bounty or looking to improve your vulnerability analysis skills, this video will help you learn how to read and understand real-world security reports like a pro.
Disclaimer: This video is for educational purposes only. The vulnerability has been responsibly disclosed and patched.
Report mentioned in the video:
https://hackerone.com/reports/2293343
⚠️ This video is for educational purposes only. The goal is to understand how vulnerabilities are found — not to exploit them. Always stay ethical and report any findings responsibly through proper channels like HackerOne or Bugcrowd.
My Course 👉 https://deadoverflow.gumroad.com/l/ma...
⚠️ Stay Responsible. Stay Ethical.
Bug bounty is a privilege. Always hack legally, get permission, and report vulnerabilities responsibly. Respect programs and their rules. Let’s make the internet safer—together.
🌐 Make sure to follow me on socials!
/ deadoverflow
/ deadoverflow
📢 Make sure to also join my discord server as well!
/ discord