CVE-2023-7028
Weak Password Recovery Mechanism for Forgotten Password in GitLab
9.8
CRITICAL
CVSS 3.1
⚠ KEVEPSS 93.4%
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
How to fix CVE-2023-7028
To remediate CVE-2023-7028, upgrade the affected package to a fixed version below.
- —upgrade to 16.1.6 or later
Is CVE-2023-7028 being exploited?
Yes — CVE-2023-7028 is on the CISA Known Exploited Vulnerabilities (KEV) catalog. Patch immediately.
Affected packages (1)
- >= 16.1.0, < 16.1.6, >= 16.2.0, < 16.2.9, >= 16.3.0, < 16.3.7, >= 16.4.0, < 16.4.5, >= 16.5.0, < 16.5.6, >= 16.6.0, < 16.6.4, >= 16.7.0, < 16.7.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |