← All CVEs

CVE-2023-3364

high · 7.5

An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads which use AutolinkFilter to the preview_markdown endpoint.

7.5
CVSS
44.5%
EPSS (exploit prob.)
99th
EPSS percentile
2023-08-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-1333

Affected products

VendorProductAffected versions
gitlabgitlab>= 8.14, < 16.0.8
gitlabgitlab>= 8.14, < 16.0.8
gitlabgitlab>= 16.1, < 16.1.3
gitlabgitlab>= 16.1, < 16.1.3
gitlabgitlab>= 16.2, < 16.2.2
gitlabgitlab>= 16.2, < 16.2.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-3364