AllCyberNews

CVE-2023-7028

Weak Password Recovery Mechanism for Forgotten Password in GitLab

CVSS 10 critical · GitLab GitLab · published 2024-01-12

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

Coverage 1 source

  1. 2026-09-14 Cybersecurity Dive critical Malicious actors already using critical GitLab flaw, CISA and others warn

    CISA and others warn of critical GitLab flaw being exploited.

Also covered