CVE-2023-2132: High severity gitlab vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by sending crafted payloads to the previewmarkdown endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2132?
CVE-2023-2132 is considered a medium severity vulnerability due to its potential for causing Denial of Service (DoS) through regular expression exploitation.
How do I fix CVE-2023-2132?
To fix CVE-2023-2132, upgrade GitLab to version 15.10.8 or later, 15.11.7 or later, or 16.0.2 or later.
What types of GitLab versions are affected by CVE-2023-2132?
CVE-2023-2132 affects all GitLab CE/EE versions starting from 15.4 before 15.10.8, from 15.11 before 15.11.7, and from 16.0 before 16.0.2.
What is the nature of the vulnerability in CVE-2023-2132?
CVE-2023-2132 is a regular expression denial of service (ReDoS) vulnerability triggered by specially crafted payloads.
Who is affected by CVE-2023-2132?
All users of GitLab Community and Enterprise Editions within the specified versions are affected by CVE-2023-2132.