CVE-2023-3900: Improper Validation of Specified Type of Input in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid 'startsha' value on merge requests page may lead to Denial of Service as Changes tab would not load.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the CVE ID for this vulnerability?
The CVE ID for this vulnerability is CVE-2023-3900.
What is the severity of CVE-2023-3900?
The severity of CVE-2023-3900 is high, with a severity value of 7.5.
What is the affected software for CVE-2023-3900?
The affected software for CVE-2023-3900 is GitLab CE/EE, with versions starting from 16.1 before 16.1.3 and versions starting from 16.2 before 16.2.2.
How does CVE-2023-3900 affect GitLab CE/EE?
CVE-2023-3900 affects GitLab CE/EE by causing a Denial of Service as the Changes tab would not load on the merge requests page due to an invalid 'start_sha' value.
Is there a fix available for CVE-2023-3900?
Yes, a fix is available for CVE-2023-3900. Users should update GitLab CE/EE to version 16.1.3 or 16.2.2 or later.