CVE-2023-7028 KEV EXPLOIT
10.0
CRITICAL · CVSS 3.1 · EPSS 94.6% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2024-05-22.
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
| EPSS | 94.65% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-640 |
| On CISA KEV | yes — remediate by 2024-05-22 |
| Public exploit | yes |
| Published | 2024-01-12 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | GitLab Community and Enterprise Editions Improper Access Control Vulnerability |
|---|---|
| Added | 2024-05-01 |
| Due | 2024-05-22 |
| Vendor / product | GitLab / GitLab CE/EE |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| gitlab | gitlab |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GitLab CE/EE < 16.7.2 - Password Reset | 2024-03-14 |
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/436084
- https://hackerone.com/reports/2293343
- https://gitlab.com/gitlab-org/gitlab/-/issues/436084
- https://hackerone.com/reports/2293343
- https://www.vicarius.io/vsociety/posts/critical-gitlab-account-takeover-vulnerability-cve-2023-7028
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7028
→ the Explorer · watch your stack · NVD