QID 379146
Date Published: 2024-01-02
QID 379146: GitLab EE Denial of Service (DoS) Vulnerability (CVE-2023-5963)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
Affected Versions:
GitLab versions starting from 13.9.0 to 16.3.6
GitLab versions starting from 16.4.0 to 16.4.1
GitLab version 16.5.0
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability can cause Denial of Service (DoS).
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Advisory
Vendor References
- GitLab Advisory -
github.com/advisories/GHSA-5rfm-2gcw-59ww
CVEs related to QID 379146
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Advisory |
|