References https://nvd.nist.gov/vuln/detail/CVE-2023-7028 https://gitlab.com/gitlab-org/gitlab/-/issues/436084 https://github.com/zan8in/pocwiki/blob/main/GitLab%E4%BB%BB%E6%84%8F%E7%94%A8%E6%88%B7%E5%AF%86%E7%A0%81%E9%87%8D%E7%BD%AE%E6%BC%8F%E6%B4%9E(CVE-2023-7028).md https://blog.nsfocus.net/gitlabcve-2023-7028/ https://zhuanlan.zhihu.com/p/680921055 https://avd.aliyun.com/detail?id=AVD-2023-7028 https://wh0am1i.com/2024/03/13/CVE-2023-7028-gitlab-takeover/index.html https://zone.huoxian.cn/d/2883-gitlab-cve-2023-7028 https://rivers.chaitin.cn/blog/cq9583h0lnechd2450eg https://www.secrss.com/articles/62746 https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/ https://github.com/RandomRobbieBF/CVE-2023-7028 https://www.rapid7.com/db/vulnerabilities/gitlab-gitlab-cve-2023-7028/ https://www.exploit-db.com/exploits/51889
Related VulnerabilitiesPoCCVE-2026-85706: GitLab CE/EE <=19.1.7/19.2.5/19.3.1 - Arbitrary File ReadGitLab CE/EE /api/graphql 未授权访问漏洞(CVE-2026-19478)PoCCVE-2026-19478: GitLab CE/EE - GraphQL @gl_introduced Arbitrary Method InvocationPoCCVE-2021-22175: GitLab CI Lint API - Server-Side Request ForgeryGitLab GitLab CE/EE 权限管理不当漏洞GitLab CE/EE GraphQL 身份验证缺陷漏洞GitLab CE/EE 资源分配控制不当漏洞 可导致拒绝服务gitlab-api-user-enum: GitLab - User Information Disclosure Via Open APIPoCCVE-2024-45409: GitLab - SAML Authentication BypassPoCCVE-2025-25291: GitLab - SAML Authentication BypassPoCCVE-2019-6793: GitLab Enterprise Edition - Server-Side Request ForgeryPoCCVE-2020-2096: Jenkins Gitlab Hook <=1.4.2 - Cross-Site ScriptingPoCCVE-2020-26413: Gitlab CE/EE 13.4 - 13.6.2 - Information Disclosure