GitLab Community and Enterprise Editions Improper Access Control Vulnerability
High Listed in CISA KEV
Summary
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- GitLab:GitLab CE/EE
Sources
- CISA KEV DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2023-7028 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/ reference
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV