CVE Vulnerabilities

CVE-2023-3900

Published: Aug 02, 2023 | Modified: Aug 04, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. An invalid start_sha value on merge requests page may lead to Denial of Service as Changes tab would not load.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 16.1 (including) 16.1.3 (excluding)
Gitlab Gitlab 16.2 (including) 16.2.2 (excluding)

References