5379 GitLab servers vulnerable to zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-7028 | Unauthenticated Account Takeover via Password Reset Flaw in GitLab CE/EE GitLab Community and Enterprise Editions contain a critical improper access control flaw (CWE-640) in which password reset emails for a user account could be delivered to an unverified email address. Because the password reset flow is reachable over the network without authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker could trigger a password reset for a victim's account such that the reset link lands on an attacker-controlled, unverified email address, then set a new password and hijack the account. Taking over an account gives the attacker that account's privileges, so compromise of an administrator account could expose the instance's code repositories, settings, and any secrets or CI/CD credentials they can reach. All GitLab CE/EE versions from 16.1 through 16.7 prior to the patched releases (16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4, and 16.7.2) are affected. The flaw is under active exploitation: it carries an EPSS of 94.6% (100th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2024-05-01, and news coverage confirms attackers are hijacking accounts in the wild. Do: Upgrade affected GitLab CE/EE instances immediately to the patched release for your track — 16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4, or 16.7.2 (or later) — prioritizing internet-facing instances given active exploitation and the KEV listing. Audit user accounts for unverified or unexpected email addresses and review logs for password reset activity to identify possible takeovers, and rotate credentials for any high-privilege accounts you suspect were compromised. | 9.8 | 95% | KEV PoC ×2 |
| largetens of thousands of internet-exposed GitLab instances (public internet-wide scan data) |
Full article361 words · extracted from securityaffairs.com · click to collapse

Thousands of GitLab servers are vulnerable to zero-click account takeover attacks exploiting the flaw CVE-2023-7028.
GitLab has recently released security updates to address two critical vulnerabilities impacting both the Community and Enterprise Edition.
The most critical vulnerability, tracked as CVE-2023-7028 (CVSS score 10), is an account takeover via Password Reset. The flaw can be exploited to hijack an account without any interaction.
“An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.” reads the advisory published by GitLab.
The flaws impact the following versions:
- 16.1 prior to 16.1.5
- 16.2 prior to 16.2.8
- 16.3 prior to 16.3.6
- 16.4 prior to 16.4.4
- 16.5 prior to 16.5.6
- 16.6 prior to 16.6.4
- 16.7 prior to 16.7.2
GitLab addressed the flaw with the releases 16.7.2, 16.5.6, and 16.6.4. The company backported security patches to 16.1.6, 16.2.9, and 16.3.7.
The company is not aware of attacks in the wild exploiting the vulnerability CVE-2023-7028. Self-managed customers are recommended to review their logs to check for possible attempts to exploit this vulnerability:
- Check gitlab-rails/production_json.log for HTTP requests to the
/users/passwordpath with params.value.email consisting of a JSON array with multiple email addresses. - Check gitlab-rails/audit_json.log for entries with meta.caller.id of PasswordsController#create and target_details consisting of a JSON array with multiple email addresses.
Over 5,300 internet-exposed GitLab instances are vulnerable to CVE-2023-7028, a zero-click account takeover flaw GitLab warned about earlier this month.
Researchers from ShadowServer reported that 5,379 instances exposed online are vulnerable to this flaw.
— Shadowserver (@Shadowserver) January 24, 2024Running GitLab? We are sharing instances vulnerable to CVE-2023-7028 (Account Takeover via Password Reset without user interactions) – 5379 instances found worldwide (on 2024-01-23). Top: US (964) & Germany (730)
Check for signs of compromise and patch: https://t.co/XqIbXO5GBp pic.twitter.com/6f3v9oHaOG
Most of the vulnerable servers are in the United States (964), Germany (730), and Russia (721).
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CVE-2023-7028)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/158075/hacking/gitlab-servers-vulnerable-cve-2023-7028.html