Back to Labs
Security Advisory

CVE-2023-7028

About

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

Weakness (CWE):CWE-640

Rainforest analyst review

GitLab's account password-reset flow could send the reset link to an unverified, attacker-supplied email address. By submitting the reset request with an additional email under their control, an attacker receives the reset token for someone else's account and takes it over. There is no exploit code or memory corruption here; it is a broken authentication-recovery path abused with ordinary form input, and it works against any account, including ones without extra protections.

GitLab is where organizations keep source code, CI/CD pipelines, deployment credentials, and secrets, so taking over an account is a direct route to intellectual property and, through pipeline access, to supply-chain compromise of everything that repository builds and ships. Accounts with two-factor authentication resist full takeover because the second factor still gates login, which makes enforced MFA the important structural defense. This is on CISA's KEV list; upgrade to the fixed 16.x releases immediately, enforce MFA on all accounts, and review reset activity and recent account changes for signs the flaw was already used against you.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2023-7028?

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

How severe is CVE-2023-7028?

CVE-2023-7028 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2023-7028 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability None.

Which products are affected by CVE-2023-7028?

Public advisories list the following as affected: gitlab. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-7028?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email