An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.
Fixes

Solution

Upgrade to version 16.3.6, 16.4.2, 16.5.1 or above.


Workaround

No workaround given by the vendor.

History

Mon, 07 Oct 2024 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Oct 2024 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 03 Oct 2024 06:30:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in GitLab Allocation of Resources Without Limits or Throttling in GitLab
Weaknesses CWE-770

Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2024-10-03T06:23:16.410Z

Reserved: 2023-11-06T12:18:51.359Z

Link: CVE-2023-5963

cve-icon Vulnrichment

Updated: 2024-08-02T08:14:25.152Z

cve-icon NVD

Status : Modified

Published: 2023-11-06T13:15:10.110

Modified: 2024-11-21T08:42:52.487

Link: CVE-2023-5963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.