QID 379182
Date Published: 2024-01-03
QID 379182: GitLab CE/EE Regular Expression Denial of Service (ReDoS) Vulnerability (CVE-2023-2232)
GitLab Inc. is an open-core company that operates GitLab, a DevOps software package which can develop, secure, and operate software
CVE-2023-2232: An issue has been discovered in GitLab leading to a ReDoS vulnerability in the Jira prefix.
Affected Versions:
GitLab CE/EE versions starting from 15.10 before 16.1
QID Detection Logic:(Authenticated)
It fires gitlab-rake gitlab:env:info command to check vulnerable version of GitLab.
Successful exploitation of this vulnerability causes Regular Expression Denial of Service (ReDoS) in the Jira prefix.
Solution
The vendor has released a patch for this vulnerability. For more information, please visit GitLab Security Advisory
Vendor References
- GitLab Security Advisory -
nvd.nist.gov/vuln/detail/CVE-2023-2232
CVEs related to QID 379182
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GitLab Security Advisory |
|