
10/11/2021 · GitLab
What this post added
This post details a vulnerability in GitKraken's key generation (versions 7.6.0 to 8.0.0) that could produce weak or duplicate SSH keys, potentially allowing unauthorized access to GitLab accounts and repositories. GitLab has responded by emailing affected users, blocking known weak keys on GitLab.com, and providing instructions for self-managed customers to revoke and regenerate their SSH keys, and for all users to update GitKraken.