← All CVEs

CVE-2023-0921

medium · 4.3

A lack of length validation in GitLab CE/EE affecting all versions from 8.3 before 15.10.8, 15.11 before 15.11.7, and 16.0 before 16.0.2 allows an authenticated attacker to create a large Issue description via GraphQL which, when repeatedly requested, saturates CPU usage.

4.3
CVSS
84.4%
EPSS (exploit prob.)
100th
EPSS percentile
2023-06-06
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Weaknesses

CWE-770

Affected products

VendorProductAffected versions
gitlabgitlab>= 8.3.0, < 15.10.8
gitlabgitlab>= 8.3.0, < 15.10.8
gitlabgitlab>= 15.11.0, < 15.11.7
gitlabgitlab>= 15.11.0, < 15.11.7
gitlabgitlab>= 16.0.0, < 16.0.2
gitlabgitlab>= 16.0.0, < 16.0.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-0921