logo

CISA Warns of Active Exploitation of Severe GitLab Password Reset Vulnerability

ID: 47c5cbe7-4584-501b-99f2-d8eda05d7cfb

STIX ID: report--47c5cbe7-4584-501b-99f2-d8eda05d7cfb

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-05-02

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

CISA added CVE-2023-7028 — a critical GitLab vulnerability (CVSS 10.0) that enables account takeover via password-reset to unverified email addresses — to its Known Exploited Vulnerabilities catalog due to active exploitation. GitLab introduced the flaw in v16.1.0 (May 1, 2023) and has released fixes in 16.5.6/16.6.4/16.7.2 and backports; federal agencies were required to apply fixes by May 22, 2024. The report warns of serious impacts including account takeover, credential theft, and possible supply-chain attacks if CI/CD or repositories are compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.