UNKNOWNKNOWN EXPLOITED
CVE-2023-7028
GitLab Community and Enterprise Editions Improper Access Control Vulnerability
Summary
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.
References
Includes data from the CISA Known Exploited Vulnerabilities catalog.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.