CVE Vulnerabilities

CVE-2023-0632

Inefficient Regular Expression Complexity

Published: Aug 02, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue has been discovered in GitLab affecting all versions starting from 15.2 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible by using crafted payloads to search Harbor Registry.

Weakness

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Software

NameVendorStart VersionEnd Version
GitlabGitlab15.2 (including)16.0.8 (excluding)
GitlabGitlab16.1 (including)16.1.3 (excluding)
GitlabGitlab16.2 (including)16.2.2 (excluding)
GitlabUbuntubionic*
GitlabUbuntuesm-apps-legacy/xenial*
GitlabUbuntuesm-apps/xenial*
GitlabUbuntutrusty*
GitlabUbuntuxenial*

Potential Mitigations

References