MEDIUM

CVE-2023-6688

Gitlab GitLab 2024-05-14 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.

Summary dbcve.org

GitLab CE/EE versions 16.11 through 16.11.1 contain a ReDoS (Regular Expression Denial of Service) vulnerability in the Google Chat Messages integration processing logic. The flawed regex handling during message processing can be exploited by specially crafted input to cause excessive CPU consumption and service degradation.

Mitigation

Upgrade GitLab to version 16.11.2 or later. If immediate upgrade is not possible, consider temporarily disabling the Google Chat integration until the patch can be applied.

Weakness (CWE)

CWE-1333

EPSS Score

0.75%
Probability of exploitation in next 30 days
53.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE