RaqibCTI
CVE

CVE-2023-7028

P2
GitLab Community and Enterprise Editions Improper Access Control Vulnerability
GitLab · GitLab CE/EE
Date added (CISA)
2024-05-01
Remediation due
2024-05-22
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

Source: NVD ↗ · CISA KEV Catalog ↗