CVE-2023-2199: High severity gitlab vulnerability
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads to the previewmarkdown endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-2199?
CVE-2023-2199 is categorized as a Regular Expression Denial of Service (ReDoS) vulnerability.
How do I fix CVE-2023-2199?
To fix CVE-2023-2199, upgrade your GitLab installation to version 15.10.8 or higher, 15.11.7 or higher, or 16.0.2 or higher.
Which versions of GitLab are affected by CVE-2023-2199?
CVE-2023-2199 affects GitLab versions from 12.0 up to 15.10.8, from 15.11.0 to 15.11.7, and from 16.0.0 to 16.0.2.
What type of attack does CVE-2023-2199 involve?
CVE-2023-2199 involves a Regular Expression Denial of Service attack via crafted payloads.
Is CVE-2023-2199 present in both GitLab CE and EE?
Yes, CVE-2023-2199 is present in both GitLab Community Edition (CE) and Enterprise Edition (EE) across the affected versions.