CVE-2023-2198: High severity gitlab vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the previewmarkdown endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2198?
CVE-2023-2198 has a moderate severity rating due to its potential to cause a Regular Expression Denial of Service.
How do I fix CVE-2023-2198?
To fix CVE-2023-2198, update GitLab to version 15.10.8, 15.11.7, or 16.0.2 or newer.
Which versions of GitLab are affected by CVE-2023-2198?
CVE-2023-2198 affects GitLab versions from 8.7 through 15.10.7, 15.11.0 through 15.11.6, and 16.0.0 through 16.0.1.
What type of vulnerability is CVE-2023-2198?
CVE-2023-2198 is classified as a Regular Expression Denial of Service vulnerability.
Is there any workaround for CVE-2023-2198?
There is currently no documented workaround for mitigating CVE-2023-2198 other than applying the provided updates.