Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.
Published: 2023-11-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to version 16.5.1, 16.4.2, 16.3.6

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-44535 An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.3 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. A Regular Expression Denial of Service was possible by adding a large string in timeout input in gitlab-ci.yml file.
History

Tue, 08 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Thu, 03 Oct 2024 06:30:00 +0000

Type Values Removed Values Added
Title Uncontrolled Resource Consumption in GitLab Inefficient Regular Expression Complexity in GitLab
Weaknesses CWE-1333

Thu, 19 Sep 2024 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Aug 2024 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2025-11-20T04:08:28.265Z

Reserved: 2023-07-25T10:30:28.870Z

Link: CVE-2023-3909

cve-icon Vulnrichment

Updated: 2024-08-02T07:08:50.675Z

cve-icon NVD

Status : Analyzed

Published: 2023-11-06T13:15:09.653

Modified: 2025-05-05T14:11:38.977

Link: CVE-2023-3909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses