CVE-2023-3904
Description
An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.
Summary dbcve.org
An integer overflow vulnerability in GitLab EE allows manipulation of the 'time spent' field on issues, causing the value to exceed its intended bounds and corrupting the data displayed in issue boards. The overflow occurs when the time tracking value exceeds the maximum integer storage capacity, leading to incorrect or unexpected issue details being shown.
Mitigation
Upgrade GitLab EE to version 16.4.4, 16.5.4, 16.6.2 or later to receive the patch for this integer overflow vulnerability.