CVE-2023-5963
CVE-2023-5963
3.1
LowPublished:
Last updated:
Source:cve@gitlab.com
Modified
Weakness (CWE)
CVSS Vector
v3.1- Attack Vector
- Network
- Attack Complexity
- High
- Privileges Required
- Low
- User Interaction
- None
- Scope
- Unchanged
- Confidentiality
- None
- Integrity
- None
- Availability
- Low
Description
An issue has been discovered in GitLab EE with Advanced Search affecting all versions from 13.9 to 16.3.6, 16.4 prior to 16.4.2 and 16.5 prior to 16.5.1 that could allow a denial of service in the Advanced Search function by chaining too many syntax operators.
References
cve@gitlab.com
https://gitlab.com/gitlab-org/gitlab/-/issues/423468af854a3a-2127-422b-91ae-364da2661108
https://gitlab.com/gitlab-org/gitlab/-/issues/423468