First published: Wed Apr 05 2023(Updated: )
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. A search timeout could be triggered if a specific HTML payload was used in the issue description.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=15.9.0<15.9.4 | |
GitLab | >=15.9.0<15.9.4 | |
GitLab | =15.10.0 | |
GitLab | =15.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-1787 has a moderate severity level due to its potential to trigger a search timeout.
To fix CVE-2023-1787, upgrade GitLab to version 15.9.4 or 15.10.1 or later.
CVE-2023-1787 affects GitLab versions 15.9.0 to 15.9.4 and 15.10.0.
The issue in CVE-2023-1787 is a search timeout triggered by a specific HTML payload in the issue description.
There are no known workarounds for CVE-2023-1787 other than upgrading to the fixed versions.