MEDIUM

CVE-2023-4912

Gitlab GitLab 2023-12-01 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab EE affecting all versions starting from 10.5 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted mermaid diagram input.

Summary dbcve.org

A client-side denial of service vulnerability exists in GitLab EE where maliciously crafted mermaid diagram input can cause the victim's browser to become unresponsive or crash. This affects all versions from 10.5 through the unpatched versions of 16.4.x, 16.5.x, and 16.6.x.

Mitigation

Upgrade GitLab EE to version 16.4.3, 16.5.3, or 16.6.1 (or later) to patch the vulnerability. Alternatively, restrict or sanitize mermaid diagram input from untrusted sources until upgrade is possible.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.58%
Probability of exploitation in next 30 days
46.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE