Vulnerability Intelligence Report
Weak Password Recovery Mechanism for Forgotten Password in GitLab
CVE-2023-7028
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:5.8
EPSS Probability:94.65%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-640 ↗CWE-640: Weak Password Recovery Mechanism for Forgotten Password
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| GitLab | GitLab | 16.1 < 16.1.6 (affected), 16.2 < 16.2.9 (affected), 16.3 < 16.3.7 (affected), 16.4 < 16.4.5 (affected), 16.5 < 16.5.6 (affected), 16.6 < 16.6.4 (affected), 16.7 < 16.7.2 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
94.647%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitLab Inc. · Vendor · USA |
| Reserved | 2023-12-20T20:30:37 |
| Published | 2024-01-12T13:56:41 |
| Last Updated | 2026-08-15T04:10:51 |
Community Chatter & Buzz