CVE-2023-3205: Inefficient Regular Expression Complexity in GitLab
An issue has been discovered in GitLab affecting all versions starting from 15.11 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. An authenticated user could trigger a denial of service when importing or cloning malicious content.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-3205.
What versions of GitLab are affected by this vulnerability?
This vulnerability affects versions starting from 15.11 before 16.1.5, versions starting from 16.2 before 16.2.5, and versions starting from 16.3 before 16.3.1 of GitLab.
How can an authenticated user trigger the denial of service?
An authenticated user can trigger the denial of service by importing or cloning malicious content.
What is the severity of CVE-2023-3205?
The severity of CVE-2023-3205 is medium with a CVSS score of 6.5.
Is there any additional information about this vulnerability?
Yes, you can find additional information about this vulnerability in the GitLab issue tracker and the HackerOne report.