HIGH

CVE-2023-3904

Gitlab GitLab 2023-12-15 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.

Summary dbcve.org

An integer overflow vulnerability in GitLab EE allows manipulation of the 'time spent' field on issues, causing the value to exceed its intended bounds and corrupting the data displayed in issue boards. The overflow occurs when the time tracking value exceeds the maximum integer storage capacity, leading to incorrect or unexpected issue details being shown.

Mitigation

Upgrade GitLab EE to version 16.4.4, 16.5.4, 16.6.2 or later to receive the patch for this integer overflow vulnerability.

Weakness (CWE)

CWE-1287

EPSS Score

0.76%
Probability of exploitation in next 30 days
53.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE