S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 25, 2024

CVE-2023-7028 Scanner

CVE-2023-7028 scanner - Account Takeover vulnerability in GitLab

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-7028
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
GitLabby GitLab
AFFECTED< 16.1.6SAFE ✓≥ 16.1.6
Updated Aug 19, 2026View on NVD →
Detail

GitLab is a popular web-based Git repository manager that is used for version control, collaboration, and code management. It allows software teams to track and manage changes to their codebase, facilitating collaboration among team members, and streamlining the software development process. The platform offers an array of features, including project management tools, issue tracking, and code review capabilities. It is widely used by software development teams in various industries, including finance, healthcare, and e-commerce.

Recently, a vulnerability identified as CVE-2023-7028 was discovered in GitLab CE/EE. This vulnerability affects all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2. The vulnerability allows user account password reset emails to be delivered to an unverified email address. An attacker could exploit this vulnerability to gain access to the target user's account by resetting the password and accessing sensitive information or maliciously using the account.

Exploitation of this vulnerability could lead to serious consequences for organizations that use GitLab, including data breaches, intellectual property theft, and reputational damage. The vulnerability could expose sensitive information including customer data, financial information, and other confidential data depending on the type of organization using the platform.

Thanks to the pro features of the s4e.io platform, users can quickly and easily learn about the vulnerabilities in their digital assets. With a comprehensive and accurate vulnerability assessment, users can stay ahead of the cyber attackers and protect their digital assets from exploitation. The platform offers a range of features, including vulnerability scanning, cloud security assessment, and threat detection. By using this platform, organizations can stay ahead of the game and protect their digital assets from cyber threats.

 

REFERENCES

Solution Advice

To protect against this vulnerability, GitLab users can take several precautions, including:

  • Update GitLab to the latest version to patch the vulnerability.
  • Enforce two-factor authentication, making it harder for attackers to gain access to user accounts.
  • Verify all email addresses used by users to ensure that password reset emails are only sent to legitimate email addresses.
  • Educate users on the risks of phishing attacks, social engineering, and other common cyber threats.
  • Implement a robust security monitoring system and regularly test the security of the platform.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.