← Back to browse · API

CVE-2023-7028

Severity
CRITICAL
CVSS
10.0
EPSS
0.94647
Risk score
58.13
CISA KEV
Yes
PoC
No
Published
2024-01-12
Modified
2026-05-26
First seen
2026-08-07
Aliases
EUVD-2023-59219, GHSA-MGG5-84CV-FC3C
Products
GitLab:GitLab 16.1 <16.1.6, GitLab:GitLab 16.2 <16.2.9, GitLab:GitLab 16.3 <16.3.7, GitLab:GitLab 16.4 <16.4.5, GitLab:GitLab 16.5 <16.5.6, GitLab:GitLab 16.6 <16.6.4, GitLab:GitLab 16.7 <16.7.2, GitLab:GitLab CE/EE
Sources
cisa.gov CVE-2023-7028
euvd EUVD-2023-59219

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

References