CVE-2023-6678Regex Denial of Service in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 93.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 12

Description

An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. It was possible for an attacker to cause a denial of service using malicious crafted content in a junit test report file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab16.916.9.4+1
NVDgitlab/gitlab16.9.016.9.4+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-26wq-535g-r2w5: An issue has been discovered in GitLab EE affecting all versions before 162024-04-12

📋Vendor Advisories

2
GitLab
CVE-2023-6678: An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting f2024-04-12
Debian
CVE-2023-6678: gitlab - An issue has been discovered in GitLab EE affecting all versions before 16.8.6, ...2023