Executive brief
GitLab Community and Enterprise Editions contain an improper access control vulnerability that allows password reset emails to be sent to unverified email addresses. An attacker can exploit this to trigger a password reset for a target account and redirect the recovery email to an address under their control, facilitating full account takeover.
Affected products
- GitLab GitLab Community Edition (CE) 16.1 to < 16.1.6, 16.2 to < 16.2.9, 16.3 to < 16.3.7, 16.4 to < 16.4.5, 16.5 to < 16.5.6, 16.6 to < 16.6.4, 16.7 to < 16.7.2
- GitLab GitLab Enterprise Edition (EE) 16.1 to < 16.1.6, 16.2 to < 16.2.9, 16.3 to < 16.3.7, 16.4 to < 16.4.5, 16.5 to < 16.5.6, 16.6 to < 16.6.4, 16.7 to < 16.7.2
Timeline
- 2024-05-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-05-01: disclosed