漏洞描述
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
about.gitlab.comhttps://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/↗x.comhttps://x.com/rwincey/status/1745659710089437368?s=20↗gitlab.comhttps://gitlab.com/gitlab-org/gitlab/-/issues/436084↗hackerone.comhttps://hackerone.com/reports/2293343↗github.comhttps://github.com/V1lu0/CVE-2023-7028↗