CVE-2023-6489Regex Denial of Service in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 93.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12

Description

A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab16.916.9.4+1
NVDgitlab/gitlab16.7.716.8.6+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2023-6489: A denial of service vulnerability was identified in GitLab CE/EE, versions 162024-04-12
GHSA
GHSA-997p-pqq2-w5f5: A denial of service vulnerability was identified in GitLab CE/EE, versions 162024-04-12

📋Vendor Advisories

2
GitLab
CVE-2023-6489: A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 whi2024-04-12
Debian
CVE-2023-6489: gitlab - A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7....2023