CVE-2023-7028

GitLab Community and Enterprise Editions Improper Access Control Vulnerability

9.8
CVSS 3.1
94.6 %
EPSS (current)
2024-05-01
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: GitLab / GitLab CE/EE

Published: 2024-01-12 · Due (CISA): 2024-05-22

CWE: CWE-640 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2023/CVE-2023-7028.yamlGitLab - Account Takeover via Password Reset–
metasploitauxiliary/admin/http/gitlab_password_reset_account_takeoverauxiliary/admin/http/gitlab_password_reset_account_takeover2024-01-11
exploitdb51889GitLab CE/EE < 16.7.2 - Password Reset2024-03-14

References only — no downloads or instructions.

Sources