CVE-2023-7028
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
- EPSS probability
- 93.38%
- CISA KEV
- Known exploited vulnerability
- CWE
- CWE-640
- Published
- 2024-01-12
- Last modified
- 2026-08-15
Affected products
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2025-6216 — Allegra calculateTokenExpDate Password Recovery Authentication Bypass Vulnerability
- CVE-2025-47646 — WordPress PSW Front-end Login & Registration plugin <= 1.13 - Broken Authentication Vulnerability
- CVE-2026-18963 — Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
- CVE-2024-8878 — Unauthenticated Password Reset
- CVE-2023-30466 — Authentication Bypass Vulnerability in Milesight Network Video Recorder (NVR)
- CVE-2022-3485 — Weak Password Recovery in ifm moneo appliance
- CVE-2024-11350 — AdForest <= 5.1.6 - Privilege Escalation via Password Reset/Account Takeover
- CVE-2022-50910 — Beehive Forum - Account Takeover