CVE-2023-6159: ReDoS in Cargo.toml blob viewer
An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a Cargo.toml containing maliciously crafted input.
Other sources
An issue has been discovered in GitLab CE/EE affecting all versions from 12.7 prior to 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1 It was possible for an attacker to trigger a Regular Expression Denial of Service via a Cargo.toml containing maliciously crafted input. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, 6.5). It is now mitigated in the latest release and is assigned CVE-2023-6159.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.6.6Fixed in 16.7.4Fixed in 16.8.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.8.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.7.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.6.6
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6159?
The severity of CVE-2023-6159 is classified as high due to its potential for Denial of Service attacks.
How do I fix CVE-2023-6159?
To fix CVE-2023-6159, update your GitLab installation to version 16.8.1 or later.
Which versions of GitLab are affected by CVE-2023-6159?
CVE-2023-6159 affects GitLab CE/EE versions from 12.7 up to, but not including, 16.6.6, 16.7 up to, but not including, 16.7.4, and 16.8.0.
What type of attack is possible with CVE-2023-6159?
CVE-2023-6159 allows an attacker to execute a Regular Expression Denial of Service via a specially crafted Cargo.toml file.
Is there a workaround for CVE-2023-6159?
There are no recommended workarounds for CVE-2023-6159; updating to a fixed version is necessary.