๐Ÿ” CVE Alert

CVE-2023-7028

CRITICAL 10.0 โš ๏ธ CISA KEV

Weak Password Recovery Mechanism for Forgotten Password in GitLab

CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CWE CWE-640
Vendor gitlab
Product gitlab
Ecosystems
Industries
Technology
Published Jan 12, 2024
Last Updated Oct 21, 2025
โš ๏ธ Actively Exploited โ€” Act Now

Get instant alerts for gitlab gitlab

This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2023-7028.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

GitLab / GitLab
16.1 < 16.1.6 16.2 < 16.2.9 16.3 < 16.3.7 16.4 < 16.4.5 16.5 < 16.5.6 16.6 < 16.6.4 16.7 < 16.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
gitlab.com: https://gitlab.com/gitlab-org/gitlab/-/issues/436084 hackerone.com: https://hackerone.com/reports/2293343 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7028 vicarius.io: https://www.vicarius.io/vsociety/posts/critical-gitlab-account-takeover-vulnerability-cve-2023-7028

Credits

Thanks [asterion04](https://hackerone.com/asterion04) for reporting this vulnerability through our HackerOne bug bounty program