CVE-2023-7028
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
git://git@gitlab.com:gitlab-org/gitlab.git, https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/7xxx/CVE-2023-7028.json, https://gitlab.com/gitlab-org/gitlab/-/issues/436084, https://hackerone.com/reports/2293343, https://nvd.nist.gov/vuln/detail/CVE-2023-7028, https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-7028, https://www.vicarius.io/vsociety/posts/critical-gitlab-account-takeover-vulnerability-cve-2023-7028
