MEDIUM
Inefficient Regular Expression Complexity in GitLab
Published Nov 6, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.60%
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.
Affected products
-
- Version 12.3StatusaffectedConstraints<16.3.6
- Version 16.4StatusaffectedConstraints<16.4.2
- Version 16.5StatusaffectedConstraints<16.5.1
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to version 16.5.1, 16.4.2, 16.3.6
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44535 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/418763 issue-trackingpermissions-requiredBroken Link
- https://hackerone.com/reports/2050269 technical-descriptionexploitpermissions-requiredPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-44535 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/418763 | issue-trackingpermissions-requiredBroken Link | |
| https://hackerone.com/reports/2050269 | technical-descriptionexploitpermissions-requiredPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Nov 6, 2023
Updated Nov 20, 2025
Reserved Jul 25, 2023
Link CVE-2023-3909
CISA Vulnrichment
Updated Jul 24, 2024
ENISA EUVD
EUVD-2023-44535 Assigner GitLab
Published Nov 6, 2023
Updated Nov 20, 2025
Exploited since n/a
Link EUVD-2023-44535