PT-2023-26824 · Gitlab · Gitlab Ce/Ee+1

Js_Noob

·

Published

2023-09-28

·

Updated

2024-10-03

·

CVE-2023-3917

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Gitlab EE and CE versions prior to 16.2.8 Gitlab EE and CE version 16.3 prior to 16.3.5 Gitlab EE and CE version 16.4 prior to 16.4.1
Description The issue allows an attacker to cause pipelines to fail, resulting in a Denial of Service. This affects all versions of Gitlab EE and CE prior to the specified versions.
Recommendations For Gitlab EE and CE versions prior to 16.2.8, update to version 16.2.8 or later. For Gitlab EE and CE version 16.3 prior to 16.3.5, update to version 16.3.5 or later. For Gitlab EE and CE version 16.4 prior to 16.4.1, update to version 16.4.1 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2023-3917
CVE-2023-3917

Affected Products

Gitlab
Gitlab Ce/Ee