CRITICAL
CVE-2023-7028
CVSS
9.8
KEV
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
Summary dbcve.org
A vulnerability in GitLab CE/EE allows password reset emails to be delivered to unverified email addresses, potentially enabling account takeover if an attacker has access to an unverified email address associated with a target user's account.
Mitigation
Upgrade GitLab to version 16.7.2, 16.6.4, 16.5.6, 16.4.5, 16.3.7, 16.2.9, or 16.1.6 or later to remediate this issue.
Weakness (CWE)
CWE-640
EPSS Score
94.65%
Probability of exploitation in next 30 days
99.9th percentile
References
https://gitlab.com/gitlab-org/gitlab/-/issues/436084
Exploit, Issue Tracking, Vendor Advisory
https://hackerone.com/reports/2293343
Permissions Required
https://www.vicarius.io/vsociety/posts/critical-gitlab-account-takeover-vulnerability-cve-2023-7028
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7028
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.