CVE-2023-6688: Inefficient Regular Expression Complexity in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.11 prior to 16.11.2. A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6688?
CVE-2023-6688 has been classified as a moderate severity vulnerability due to its potential for denial of service attacks.
How do I fix CVE-2023-6688?
To remediate CVE-2023-6688, upgrade your GitLab installation to version 16.11.2 or later.
Which versions of GitLab are affected by CVE-2023-6688?
CVE-2023-6688 affects all GitLab CE/EE versions starting from 16.11.0 up to but not including 16.11.2.
What kind of attack does CVE-2023-6688 enable?
CVE-2023-6688 may allow for a regular expression denial-of-service (DoS) attack on the server.
What integration is vulnerable in CVE-2023-6688?
The vulnerability in CVE-2023-6688 is related to the processing logic in the Google Chat Messages integration.