CVE-2023-7028

CVE Published 2024-01-12
Related CWE(s) CWE-284: Improper Access Control, CWE-640: Weak Password Recovery Mechanism for Forgotten Password
Related Vendor(s) gitlab
Related Product(s) gitlab
Exploitation Reported (CISA KEV) 2024-05-01
CVSS 3 Base Score 10.0 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References