claytonvantol.us
SESSION: secure TLS: 1.3 PID: 1337

clayton@site:~/news$ cat cve-2023-7028-gitlab-gitlab-ceee.log

CVE-2023-7028 — GitLab Community and Enterprise Editions Improper Access Control Vulnerability

2024-05-01 • CISA Known Exploited Vulnerability


[event] GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.

> AFFECTED SOFTWARE

Field Value
Vendor GitLab
Product GitLab CE/EE
CWE CWE-284
CVE ID CVE-2023-7028
Date Added 2024-05-01
Due Date 2024-05-22
Ransomware Campaign Unknown

> MITIGATION

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Due Date: 2024-05-22

> REFERENCES


← back to terminal

UPTIME: 1337d v2.0.1 privacy LAST LOGIN: 2026-05-30 20:36:10 UTC