CVE-2023-7028 - GitLab Audit Password Reset Multiple Emails
Description
Attackers are exploiting a Critical (CVSS 10.0) GitLab vulnerability in which user account password reset emails could be delivered to an unverified email address.
Query · python
import json
def rule(event):
custom_message = event.deep_get("detail", "custom_message", default="")
emails_raw = event.deep_get("detail", "target_details", default="")
if custom_message != "Ask for password reset":
return False
try:
emails = json.loads(emails_raw)
except json.decoder.JSONDecodeError:
return False
if len(emails) > 1:
return True
return False
def title(event):
emails = event.deep_get("detail", "target_details", default="")
return f"[GitLab] Multiple password reset emails requested for {emails}"