CRITICAL

CVE-2023-7028

Gitlab GitLab 2024-01-12 CVSS v3.1
CVSS
9.8
KEV

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

Summary dbcve.org

A vulnerability in GitLab CE/EE allows password reset emails to be delivered to unverified email addresses, potentially enabling account takeover if an attacker has access to an unverified email address associated with a target user's account.

Mitigation

Upgrade GitLab to version 16.7.2, 16.6.4, 16.5.6, 16.4.5, 16.3.7, 16.2.9, or 16.1.6 or later to remediate this issue.

Proof of Concept

Weakness (CWE)

CWE-640

EPSS Score

94.65%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE