MEDIUM

CVE-2023-6736

Gitlab GitLab 2024-02-07 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

Summary dbcve.org

A client-side denial of service vulnerability in GitLab EE allows attackers to embed malicious crafted content in CODEOWNERS files that causes the viewer's browser to crash or become unresponsive when the file is rendered in the GitLab UI.

Mitigation

Upgrade GitLab to version 16.7.6, 16.8.3, 16.9.1 or later to patch this vulnerability. As a temporary workaround, avoid opening untrusted CODEOWNERS files from unknown sources.

Weakness (CWE)

CWE-1333

EPSS Score

0.64%
Probability of exploitation in next 30 days
49.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE