CVE-2023-6682: Inefficient Regular Expression Complexity in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6682?
CVE-2023-6682 has a moderate severity level due to potential impacts on GitLab's Discord Integrations.
How do I fix CVE-2023-6682?
To fix CVE-2023-6682, upgrade your GitLab installation to version 16.9.7, 16.10.5, or 16.11.2 or later.
Which versions of GitLab are affected by CVE-2023-6682?
CVE-2023-6682 affects GitLab CE/EE versions from 16.9.0 to 16.9.6, 16.10.0 to 16.10.4, and 16.11.0 to 16.11.1.
What are the impacts associated with CVE-2023-6682?
The impact of CVE-2023-6682 includes potential exploitation of the processing logic for Discord Integrations Chat Messages.
Is there a workaround for CVE-2023-6682?
There are no official workarounds for CVE-2023-6682, so upgrading is the recommended solution.