CVE-2023-6736

An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.
References
Link Resource
https://gitlab.com/gitlab-org/gitlab/-/issues/435036 Issue Tracking Vendor Advisory
https://hackerone.com/reports/2269023 Permissions Required Technical Description
https://gitlab.com/gitlab-org/gitlab/-/issues/435036 Issue Tracking Vendor Advisory
https://hackerone.com/reports/2269023 Permissions Required Technical Description
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 08:44

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/gitlab/-/issues/435036 - Issue Tracking, Vendor Advisory () https://gitlab.com/gitlab-org/gitlab/-/issues/435036 - Issue Tracking, Vendor Advisory
References () https://hackerone.com/reports/2269023 - Permissions Required, Technical Description () https://hackerone.com/reports/2269023 - Permissions Required, Technical Description

08 Oct 2024, 19:00

Type Values Removed Values Added
CWE CWE-400
References () https://gitlab.com/gitlab-org/gitlab/-/issues/435036 - Issue Tracking, Permissions Required () https://gitlab.com/gitlab-org/gitlab/-/issues/435036 - Issue Tracking, Vendor Advisory

03 Oct 2024, 07:15

Type Values Removed Values Added
CWE CWE-1333

04 Mar 2024, 20:33

Type Values Removed Values Added
First Time Gitlab
Gitlab gitlab
References () https://gitlab.com/gitlab-org/gitlab/-/issues/435036 - () https://gitlab.com/gitlab-org/gitlab/-/issues/435036 - Issue Tracking, Permissions Required
References () https://hackerone.com/reports/2269023 - () https://hackerone.com/reports/2269023 - Permissions Required, Technical Description
CPE cpe:2.3:a:gitlab:gitlab:16.9.0:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

26 Feb 2024, 21:15

Type Values Removed Values Added
Summary An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.6.7, all versions starting from 16.7 before 16.7.5, all versions starting from 16.8 before 16.8.2. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file. An issue has been discovered in GitLab EE affecting all versions starting from 11.3 before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for an attacker to cause a client-side denial of service using malicious crafted content in the CODEOWNERS file.

07 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-07 22:15

Updated : 2024-11-21 08:44


NVD link : CVE-2023-6736

Mitre link : CVE-2023-6736

CVE.ORG link : CVE-2023-6736


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-1333

Inefficient Regular Expression Complexity