HIGH
CVE-2023-0632
CVSS
7.5
Description
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.
Summary dbcve.org
A Regular Expression Denial of Service (ReDoS) vulnerability exists in GitLab's Harbor Registry search functionality. Attackers can send specially crafted regex payloads that cause excessive computational consumption, potentially rendering the service unavailable.
Mitigation
Upgrade GitLab to version 16.0.8, 16.1.3, 16.2.2 or later to remediate this vulnerability.
Weakness (CWE)
CWE-1333
EPSS Score
0.92%
Probability of exploitation in next 30 days
58.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.