CVE-2023-7028
KEVCRITICAL 10.0EPSS 94.6%
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N - EPSS
- 94.65% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-05-01
- Nuclei
- high
- Published
- 2024-01-12
- Updated
- 2026-08-15
Proof-of-concept exploits (21)
- https://www.vicarius.io/vsociety/posts/critical-gitlab-account-takeover-vulnerability-cve…
- https://hackerone.com/reports/2293343
- KameliaZaman/Exploiting-GitLab-CVE-2023-70280★ · 2025-08-05
- RandomRobbieBF/CVE-2023-702858★ · 2024-01-12
- Shimon03/CVE-2023-7028-Account-Take-Over-Gitlab0★ · 2024-01-23
- Sornphut/CVE-2023-7028-GitLab0★ · 2025-03-29
- Trackflaw/CVE-2023-7028-Docker3★ · 2024-01-25
- Vozec/CVE-2023-7028245★ · 2024-01-13
- duy-31/CVE-2023-70283★ · 2024-01-12
- fa-rrel/CVE-2023-70281★ · 2024-08-21
- gh-ost00/CVE-2023-70281★ · 2024-08-21
- googlei1996/CVE-2023-70280★ · 2024-01-12
- hackeremmen/gitlab-exploit1★ · 2024-01-28
- mochammadrafi/CVE-2023-70280★ · 2024-01-26
- olebris/Exploit_CVE_2023_7028-0★ · 2024-06-28
- sariamubeen/CVE-2023-70283★ · 2025-02-17
- soltanali0/CVE-2023-70280★ · 2024-07-25
- szybnev/CVE-2023-70281★ · 2025-07-21
- thanhlam-attt/CVE-2023-70282★ · 2024-01-23
- yoryio/CVE-2023-70280★ · 2024-12-19
- k3ppf0r/2024-PocLib