CVE-2023-1787: Medium severity gitlab vulnerability
Published Apr 5, 2023
·Updated
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.
Affected Software
4 affected components
GitLab GitLab>=15.9.0<15.9.4
GitLab GitLab>=15.9.0<15.9.4
GitLab GitLab=15.10.0
GitLab GitLab=15.10.0
Event History
Apr 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-1787?
CVE-2023-1787 has a moderate severity level due to its potential to trigger a search timeout.
2
How do I fix CVE-2023-1787?
To fix CVE-2023-1787, upgrade GitLab to version 15.9.4 or 15.10.1 or later.
3
What versions of GitLab are affected by CVE-2023-1787?
CVE-2023-1787 affects GitLab versions 15.9.0 to 15.9.4 and 15.10.0.
4
What is the nature of the issue in CVE-2023-1787?
The issue in CVE-2023-1787 is a search timeout triggered by a specific HTML payload in the issue description.
5
Is there a known workaround for CVE-2023-1787?
There are no known workarounds for CVE-2023-1787 other than upgrading to the fixed versions.