CVE-2023-0632: Inefficient Regular Expression Complexity in GitLab
An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-0632?
CVE-2023-0632 is a vulnerability discovered in GitLab that affects all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, and all versions starting from 16.2 before 16.2.2.
What is the severity of CVE-2023-0632?
CVE-2023-0632 has a severity rating of high with a CVSS score of 7.5.
How does CVE-2023-0632 affect GitLab?
CVE-2023-0632 allows a Regular Expression Denial of Service by using crafted payloads to search Harbor Registry.
Which versions of GitLab are affected by CVE-2023-0632?
All versions of GitLab starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, and all versions starting from 16.2 before 16.2.2 are affected by CVE-2023-0632.
How can I fix CVE-2023-0632?
To fix CVE-2023-0632, update GitLab to version 16.0.8, 16.1.3, or 16.2.2 or later.