HIGH
CVE-2023-3900
CVSS
7.5
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'start_sha' value on merge requests page may lead to Denial of Service as Changes tab would not load.
Summary dbcve.org
An input validation vulnerability in GitLab CE/EE allows attackers to cause a Denial of Service by providing an invalid 'start_sha' parameter value on merge request pages, causing the Changes tab to fail to load.
Mitigation
Upgrade GitLab to version 16.1.3, 16.2.2, or later. Alternatively, implement input validation for the start_sha parameter to reject malformed or invalid SHA values before processing.
Weakness (CWE)
CWE-1287
EPSS Score
0.92%
Probability of exploitation in next 30 days
58.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.