First published: Fri Sep 29 2023(Updated: )
Denial of Service in pipelines affecting all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 allows attacker to cause pipelines to fail.
Credit: cve@gitlab.com cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab GitLab | <16.2.8 | |
GitLab GitLab | <16.2.8 | |
GitLab GitLab | >=16.3.0<16.3.5 | |
GitLab GitLab | >=16.3.0<16.3.5 | |
GitLab GitLab | =16.4.0 | |
GitLab GitLab | =16.4.0 |
Upgrade to version 16.4.1, 16.3.5 or 16.2.8
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3917 is a vulnerability in Gitlab EE and CE prior to version 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1 that allows attackers to cause denial of service (DoS) in pipelines, causing them to fail.
CVE-2023-3917 affects all versions of Gitlab EE and CE prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1.
CVE-2023-3917 has a severity rating of 7.5 (high).
To fix CVE-2023-3917, it is recommended to upgrade to Gitlab version 16.2.8, 16.3.5, or 16.4.1 or later.
You can find more information about CVE-2023-3917 on the Gitlab issue page (https://gitlab.com/gitlab-org/gitlab/-/issues/417896) and the HackerOne report (https://hackerone.com/reports/2055158).