{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-7028",
  "revision": 1,
  "title": "GitLab — password reset sent to an unverified address",
  "summary": "GitLab delivered account password reset mail to an address the user had never confirmed, so anyone able to add one took the account over. Community and Enterprise builds from 16.1 through 16.7.1 are affected, and the attack needs no credentials.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.94647,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": true,
    "attack_complexity": "low",
    "kev_added": "2024-05-01",
    "prerequisites": "The attacker needs the target's account name and network access to the instance."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "GitLab >= 16.7.2",
      "GitLab >= 16.6.4",
      "GitLab >= 16.5.6",
      "GitLab >= 16.4.5",
      "GitLab >= 16.3.7",
      "GitLab >= 16.2.9",
      "GitLab >= 16.1.6"
    ]
  },
  "mitre_attack": [
    "T1098"
  ],
  "kill_chain": "credential_access",
  "recommended_action": "Upgrade GitLab to one of the fixed releases, then review recent password resets for addresses nobody recognises and require two-factor sign-in on every account.",
  "confidence": "medium",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-7028",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-7028",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-7028",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-7028",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "exploit",
      "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/436084"
    },
    {
      "type": "exploit",
      "url": "https://www.vicarius.io/vsociety/posts/critical-gitlab-account-takeover-vulnerability-cve-2023-7028"
    }
  ],
  "published_at": "2024-01-12T14:15:49.420Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "gitlab",
    "account-takeover",
    "password-reset",
    "devops",
    "kev"
  ]
}
