QID 379181
Date Published: 2024-01-02
QID 379181: GitLab CE/EE Denial of Service (DoS) Vulnerability (CVE-2023-3210)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-3210: An authenticated user could trigger a denial of service when importing or cloning malicious content.
Affected Versions:
GitLab CE/EE versions starting from 15.11 before 16.1.5
GitLab CE/EE versions starting from 16.2 before 16.2.5
GitLab CE/EE version 16.3.0
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability causes Denial of Service (DoS)
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Security Advisory
Vendor References
- GitLab Security Advisory -
nvd.nist.gov/vuln/detail/CVE-2023-3210
CVEs related to QID 379181
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Advisory |
|