CVE-2023-3904: Unvalidated timeSpent value leads to unable to load issues on Issue board
An issue has been discovered in GitLab EE affecting all versions starting before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible to overflow the time spent on an issue that altered the details shown in the issue boards.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.5.4Fixed in 16.6.2 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 16.4.4 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 16.5.4 - Upgrade
Upgrade
GitLab EEto a version that resolves this vulnerability.Fixed in 16.6.2
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-3904?
CVE-2023-3904 is classified as a medium severity vulnerability affecting certain versions of GitLab EE.
How do I fix CVE-2023-3904?
To fix CVE-2023-3904, update GitLab EE to versions 16.4.4, 16.5.4, or 16.6.2 or later.
What versions of GitLab are affected by CVE-2023-3904?
CVE-2023-3904 affects GitLab EE versions before 16.4.4, between 16.5 and 16.5.4, and between 16.6 and 16.6.2.
What is the impact of CVE-2023-3904?
The impact of CVE-2023-3904 includes an overflow of the time spent on an issue, potentially altering issue details.
Is CVE-2023-3904 fixed in the latest GitLab version?
Yes, CVE-2023-3904 is fixed in the latest GitLab versions 16.4.4, 16.5.4, and 16.6.2.