HIGH
Inefficient Regular Expression Complexity in GitLab
Published Aug 1, 2023
7.5
HIGHCVSS 3.1
EPSS 44.49%
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use AutolinkFilter to the preview_markdown endpoint.
Affected products
-
- Version 16.1StatusaffectedConstraints<16.1.3
- Version 16.2StatusaffectedConstraints<16.2.2
- Version 8.14StatusaffectedConstraints<16.0.8
- Version
No data.
Red Hat OpenShift Container Platform 4
openshift4/ose-console
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 16.2.2, 16.1.3, 16.0.8 or above.
Red Hat statement
The GitLab package used in OpenShift is a GitLab API NodeJS library which is not affected by CVE-2023-3364.
Weaknesses (1)
References (7)
- https://access.redhat.com/security/cve/CVE-2023-3364 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2228517 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44031 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/415995 issue-trackingBroken Link
- https://hackerone.com/reports/1959727 technical-descriptionexploitpermissions-requiredPermissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2023-3364
- https://www.cve.org/CVERecord?id=CVE-2023-3364
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-3364 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2228517 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44031 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/415995 | issue-trackingBroken Link | |
| https://hackerone.com/reports/1959727 | technical-descriptionexploitpermissions-requiredPermissions Required | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-3364 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-3364 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Aug 1, 2023
Updated Nov 20, 2025
Reserved Jun 22, 2023
Link CVE-2023-3364
CISA Vulnrichment
Updated Aug 30, 2024
ENISA EUVD
EUVD-2023-44031 Assigner GitLab
Published Aug 1, 2023
Updated Nov 20, 2025
Exploited since n/a
Link EUVD-2023-44031