CVE-2023-7028
GitLab Community and Enterprise Editions Improper Access Control Vulnerability
9.8
CVSS 3.1
94.6 %
EPSS (current)
2024-05-01
KEV addition
No
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: GitLab / GitLab CE/EE
Published: 2024-01-12 · Due (CISA): 2024-05-22
CWE: CWE-640 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| nuclei | http/cves/2023/CVE-2023-7028.yaml | GitLab - Account Takeover via Password Reset | – |
| metasploit | auxiliary/admin/http/gitlab_password_reset_account_takeover | auxiliary/admin/http/gitlab_password_reset_account_takeover | 2024-01-11 |
| exploitdb | 51889 | GitLab CE/EE < 16.7.2 - Password Reset | 2024-03-14 |
References only — no downloads or instructions.