Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.936
EPSS Ranking 99.8%
CVSS Severity
CVSS v3 Score 10.0
Proposed Action
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.
Ransomware Campaign
Unknown
Products affected by CVE-2023-7028
  • Gitlab » Gitlab » Version: 16.1.0
    cpe:2.3:a:gitlab:gitlab:16.1.0
  • Gitlab » Gitlab » Version: 16.1.1
    cpe:2.3:a:gitlab:gitlab:16.1.1
  • Gitlab » Gitlab » Version: 16.1.2
    cpe:2.3:a:gitlab:gitlab:16.1.2
  • Gitlab » Gitlab » Version: 16.1.3
    cpe:2.3:a:gitlab:gitlab:16.1.3
  • Gitlab » Gitlab » Version: 16.1.5
    cpe:2.3:a:gitlab:gitlab:16.1.5
  • Gitlab » Gitlab » Version: 16.2.0
    cpe:2.3:a:gitlab:gitlab:16.2.0
  • Gitlab » Gitlab » Version: 16.2.1
    cpe:2.3:a:gitlab:gitlab:16.2.1
  • Gitlab » Gitlab » Version: 16.2.2
    cpe:2.3:a:gitlab:gitlab:16.2.2
  • Gitlab » Gitlab » Version: 16.2.5
    cpe:2.3:a:gitlab:gitlab:16.2.5
  • Gitlab » Gitlab » Version: 16.2.8
    cpe:2.3:a:gitlab:gitlab:16.2.8
  • Gitlab » Gitlab » Version: 16.3.0
    cpe:2.3:a:gitlab:gitlab:16.3.0
  • Gitlab » Gitlab » Version: 16.3.4
    cpe:2.3:a:gitlab:gitlab:16.3.4
  • Gitlab » Gitlab » Version: 16.3.5
    cpe:2.3:a:gitlab:gitlab:16.3.5
  • Gitlab » Gitlab » Version: 16.3.6
    cpe:2.3:a:gitlab:gitlab:16.3.6
  • Gitlab » Gitlab » Version: 16.4.0
    cpe:2.3:a:gitlab:gitlab:16.4.0
  • Gitlab » Gitlab » Version: 16.4.1
    cpe:2.3:a:gitlab:gitlab:16.4.1
  • Gitlab » Gitlab » Version: 16.4.2
    cpe:2.3:a:gitlab:gitlab:16.4.2
  • Gitlab » Gitlab » Version: 16.4.3
    cpe:2.3:a:gitlab:gitlab:16.4.3
  • Gitlab » Gitlab » Version: 16.4.4
    cpe:2.3:a:gitlab:gitlab:16.4.4
  • Gitlab » Gitlab » Version: 16.5.0
    cpe:2.3:a:gitlab:gitlab:16.5.0
  • Gitlab » Gitlab » Version: 16.5.1
    cpe:2.3:a:gitlab:gitlab:16.5.1
  • Gitlab » Gitlab » Version: 16.5.2
    cpe:2.3:a:gitlab:gitlab:16.5.2
  • Gitlab » Gitlab » Version: 16.5.3
    cpe:2.3:a:gitlab:gitlab:16.5.3
  • Gitlab » Gitlab » Version: 16.5.4
    cpe:2.3:a:gitlab:gitlab:16.5.4
  • Gitlab » Gitlab » Version: 16.6.0
    cpe:2.3:a:gitlab:gitlab:16.6.0
  • Gitlab » Gitlab » Version: 16.6.1
    cpe:2.3:a:gitlab:gitlab:16.6.1
  • Gitlab » Gitlab » Version: 16.6.2
    cpe:2.3:a:gitlab:gitlab:16.6.2
  • Gitlab » Gitlab » Version: 16.7.0
    cpe:2.3:a:gitlab:gitlab:16.7.0
  • Gitlab » Gitlab » Version: 16.7.1
    cpe:2.3:a:gitlab:gitlab:16.7.1


Contact Us

Shodan ® - All rights reserved