CVE-2023-5963Allocation of Resources Without Limits or Throttling in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.0%
top 97.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 6

Description

An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5gitlab/gitlab13.916.3.6+1
NVDgitlab/gitlab16.4.016.4.2+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-5rfm-2gcw-59ww: An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 132023-11-06

📋Vendor Advisories

2
GitLab
CVE-2023-5963: An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.52023-11-06
Debian
CVE-2023-5963: gitlab - An issue has been discovered in GitLab EE with Advanced Search affecting all ver...2023