CVE-2023-3364
high · 7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use AutolinkFilter to the preview_markdown endpoint.
7.5
CVSS
44.5%
EPSS (exploit prob.)
99th
EPSS percentile
2023-08-02
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-1333
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| gitlab | gitlab | >= 8.14, < 16.0.8 |
| gitlab | gitlab | >= 8.14, < 16.0.8 |
| gitlab | gitlab | >= 16.1, < 16.1.3 |
| gitlab | gitlab | >= 16.1, < 16.1.3 |
| gitlab | gitlab | >= 16.2, < 16.2.2 |
| gitlab | gitlab | >= 16.2, < 16.2.2 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-3364