CVE-2023-6682
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.
Summary dbcve.org
A regular expression denial of service (ReDoS) vulnerability exists in GitLab's Discord Integration chat message processing. Specifically, the regex pattern used to parse Discord chat messages contains a flaw that can cause catastrophic backtracking when processing specially crafted input, leading to server resource exhaustion.
Mitigation
Upgrade to GitLab versions 16.9.7, 16.10.5, or 16.11.2 or later. As a temporary measure, consider disabling or rate-limiting Discord integrations until patching can be completed.