CVE-2023-0632
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2023-0632 is a vulnerability affecting multiple versions of GitLab, specifically those starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, and all versions starting from 16.2 before 16.2.2. This issue involves a Regular Expression Denial of Service (ReDoS), allowing attackers to overload GitLab's resources by using crafted payloads while searching the Harbor Registry. Successful exploitation could lead to a denial-of-service condition, potentially impacting the availability of the affected GitLab instance. Users are advised to upgrade to the latest patched versions to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
Affected Vendors
- GitLab Inc.