QID 379244
Date Published: 2024-01-12
QID 379244: GitLab EE/CE Improper Authorization Vulnerability (CVE-2023-7028)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-7028: Account Takeover via Password Reset without user interactions.
Affected Versions:
GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2.
QID Detection Logic:(Authenticated)(Linux)
The QID fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability can lead to takeover of user accounts.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Releases
Vendor References
CVEs related to QID 379244
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-7028 |
|