MEDIUM

CVE-2023-6682

Gitlab GitLab 2024-05-14 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.

Summary dbcve.org

A regular expression denial of service (ReDoS) vulnerability exists in GitLab's Discord Integration chat message processing. Specifically, the regex pattern used to parse Discord chat messages contains a flaw that can cause catastrophic backtracking when processing specially crafted input, leading to server resource exhaustion.

Mitigation

Upgrade to GitLab versions 16.9.7, 16.10.5, or 16.11.2 or later. As a temporary measure, consider disabling or rate-limiting Discord integrations until patching can be completed.

Weakness (CWE)

CWE-1333

EPSS Score

0.75%
Probability of exploitation in next 30 days
53.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE