Vulnerabilities > Gitlab > Gitlab > 16.5.4

DATE CVE VULNERABILITY TITLE RISK
2024-01-12 CVE-2023-7028 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gitlab
An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.
network
low complexity
gitlab CWE-640
critical
9.8
2023-12-01 CVE-2023-6033 Cross-site Scripting vulnerability in Gitlab
Improper neutralization of input in Jira integration configuration in GitLab CE/EE, affecting all versions from 15.10 prior to 16.6.1, 16.5 prior to 16.5.3, and 16.4 prior to 16.4.3 allows attacker to execute javascript in victim's browser.
network
low complexity
gitlab CWE-79
5.4
2023-08-30 CVE-2023-4522 Unspecified vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions before 16.2.0.
network
low complexity
gitlab
5.3