CVE-2023-7028: GitLab Community and Enterprise Editions Improper Access Control Vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
Other sources
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.
— CISA
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.1.6Fixed in 16.2.9Fixed in 16.3.7Fixed in 16.4.5Fixed in 16.5.6Fixed in 16.6.4Fixed in 16.7.2 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.7.2 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.6.4 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.5.6 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.4.5 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.3.7 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.2.9 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 16.1.6
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-7028?
The severity of CVE-2023-7028 is currently classified as critical due to the potential for account takeover through zero-click attacks.
How do I fix CVE-2023-7028?
To fix CVE-2023-7028, update GitLab to version 16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4, or 16.7.2, or later.
What versions are affected by CVE-2023-7028?
CVE-2023-7028 affects all GitLab CE/EE versions from 16.1.0 to prior versions specified up to 16.7.2.
Who is impacted by CVE-2023-7028?
All users of GitLab CE/EE running affected versions prior to the fix are at risk of this vulnerability.
Is CVE-2023-7028 being actively exploited?
Yes, CVE-2023-7028 is reported to be actively exploited in the wild, increasing the urgency for users to apply updates.