First published: Wed Jun 28 2023(Updated: )
An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab | >=15.10<16.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-2232 is categorized as a high severity vulnerability due to its potential for denial-of-service attacks through regular expression denial of service (ReDoS).
To mitigate CVE-2023-2232, upgrade your GitLab version to 16.1 or later as it resolves the identified vulnerability.
CVE-2023-2232 affects all GitLab versions from 15.10 up to, but not including, 16.1.
CVE-2023-2232 is a ReDoS (Regular Expression Denial of Service) vulnerability affecting the Jira prefix processing in GitLab.
While you can continue to use GitLab with CVE-2023-2232, it is highly recommended to upgrade to a fixed version to avoid potential denial-of-service issues.