HIGH

CVE-2023-0632

Gitlab GitLab 2023-08-02 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

Summary dbcve.org

A Regular Expression Denial of Service (ReDoS) vulnerability exists in GitLab's Harbor Registry search functionality. Attackers can send specially crafted regex payloads that cause excessive computational consumption, potentially rendering the service unavailable.

Mitigation

Upgrade GitLab to version 16.0.8, 16.1.3, 16.2.2 or later to remediate this vulnerability.

Weakness (CWE)

CWE-1333

EPSS Score

0.92%
Probability of exploitation in next 30 days
58.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE