An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 03 Oct 2024 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Improper Access Control in GitLab | Weak Password Recovery Mechanism for Forgotten Password in GitLab |
Thu, 19 Sep 2024 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Metrics |
kev
|
Fri, 30 Aug 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-284 |
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Mon, 19 Aug 2024 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2024-01-12T13:56:41.726Z
Updated: 2024-10-03T06:23:17.513Z
Reserved: 2023-12-20T20:30:37.127Z
Link: CVE-2023-7028
Vulnrichment
Updated: 2024-08-19T07:48:03.820Z
NVD
Status : Analyzed
Published: 2024-01-12T14:15:49.420
Modified: 2024-12-20T19:05:19.913
Link: CVE-2023-7028
Redhat
No data.