CVE-2023-3900

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Aug 2, 2023
Updated: Aug 4, 2023
CWE ID 20

Summary

CVE-2023-3900 is a Denial of Service vulnerability affecting GitLab CE and EE versions starting from 16.1 before 16.1.3 and all versions of 16.2 before 16.2.2. This issue arises when an incorrect 'start_sha' value is entered on the merge requests page. Consequentially, the Changes tab fails to load, leading to a disruption in the functionality of the GitLab platform. This vulnerability may result in significant downtime and productivity loss until the affected component is updated to a patch release.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share