CVE-2023-5963: Allocation of Resources Without Limits or Throttling in GitLab
An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-5963.
What is the title of this vulnerability?
The title of this vulnerability is Improper Input Validation in GitLab.
What is the description of this vulnerability?
This vulnerability in GitLab EE with Advanced Search could allow a denial of service in the Advanced Search function by chaining too many syntax operators.
Which versions of GitLab EE are affected by this vulnerability?
All versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1 are affected by this vulnerability.
What is the severity of CVE-2023-5963?
The severity of CVE-2023-5963 is medium with a CVSS score of 4.3.
How can this vulnerability be exploited?
This vulnerability can be exploited by chaining too many syntax operators in the Advanced Search function of GitLab EE.
Is there a fix available for this vulnerability?
Yes, a fix is available in versions 16.4.2 and 16.5.1 of GitLab EE.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following reference: https://gitlab.com/gitlab-org/gitlab/-/issues/423468
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-20.