Skip to content
COOEY

EXPOSURES › CVE-2023-7028

CVE-2023-7028

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-05-01 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-7028 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildunpatchedauth-bypass

GitLab exploited an access control flaw to send password reset emails to unverified addresses, enabling account takeovers.

This improper access control vulnerability allowed attackers to bypass email verification requirements and trigger password resets for unverified accounts, facilitating account takeovers. For DIB organizations using GitLab for CI/CD or code management, this exposes sensitive credentials and source code to unauthorized access, requiring immediate patching and verification of email verification workflows.

Shame score — A critical access control flaw that was actively exploited but did not involve remote code execution or supply chain compromise.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.