CVE-2023-7028
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- GitLab Community and Enterprise Editions Improper Access Control Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 95% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-640
מוצרים מושפעים
gitlab: gitlab
קישורים
- https://gitlab.com/gitlab-org/gitlab/-/issues/436084 ExploitIssue TrackingVendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/436084 ExploitIssue TrackingVendor Advisory
- https://www.vicarius.io/vsociety/posts/critical-gitlab-account-takeover-vulner… ExploitThird Party Advisory
- https://hackerone.com/reports/2293343 Permissions Required
- https://hackerone.com/reports/2293343 Permissions Required
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource