Security
Loading…

CVE-2023-7028

UNKNOWNKnown Exploited
Description

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

Timeline
Published:May 1st, 2024 12:00 AM
Last modified:May 1st, 2024 12:00 AM
Added to KEV:May 1st, 2024
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

GitLab

Products

GitLab CE/EE
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute