CVE-2023-7028
critical · 10Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Weaknesses
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| gitlab | gitlab | >= 16.1.0, < 16.1.6 |
| gitlab | gitlab | >= 16.1.0, < 16.1.6 |
| gitlab | gitlab | >= 16.2.0, < 16.2.9 |
| gitlab | gitlab | >= 16.2.0, < 16.2.9 |
| gitlab | gitlab | >= 16.3.0, < 16.3.7 |
| gitlab | gitlab | >= 16.3.0, < 16.3.7 |
| gitlab | gitlab | >= 16.4.0, < 16.4.5 |
| gitlab | gitlab | >= 16.4.0, < 16.4.5 |
| gitlab | gitlab | >= 16.5.0, < 16.5.6 |
| gitlab | gitlab | >= 16.5.0, < 16.5.6 |
| gitlab | gitlab | >= 16.6.0, < 16.6.4 |
| gitlab | gitlab | >= 16.6.0, < 16.6.4 |
| gitlab | gitlab | >= 16.7.0, < 16.7.2 |
| gitlab | gitlab | >= 16.7.0, < 16.7.2 |
Check a specific version with /api/v1/cve/match.
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/436084
- https://hackerone.com/reports/2293343
- https://gitlab.com/gitlab-org/gitlab/-/issues/436084
- https://hackerone.com/reports/2293343
- https://www.vicarius.io/vsociety/posts/critical-gitlab-account-takeover-vulnerability-cve-2023-7028
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7028
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-7028